2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-23759CRITICAL9.8Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" paramete...
CVE-2024-23512CRITICAL9.8Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.T...
CVE-2024-24797CRITICAL9.8Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue...
CVE-2024-23513CRITICAL9.8Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.
CVE-2024-25100CRITICAL9.8Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue ...
CVE-2024-25722CRITICAL9.8qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
CVE-2024-25718CRITICAL9.8In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which int...
CVE-2024-25714CRITICAL9.8In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attack...
CVE-2024-23724CRITICAL9Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any acco...
CVE-2024-25316CRITICAL9.8Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?...
CVE-2024-25315CRITICAL9.8Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2...
CVE-2024-25314CRITICAL9.8Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
CVE-2024-25307CRITICAL9.8Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/boo...
CVE-2024-25302CRITICAL9.8Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
CVE-2024-25678CRITICAL9.8In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
CVE-2024-25675CRITICAL9.8An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process...
CVE-2024-25674CRITICAL9.8An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the...
CVE-2024-21762CRITICAL9.8A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0...
CVE-2024-24308CRITICAL9.8SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows re...
CVE-2024-1353CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the fun...
CVE-2024-24393CRITICAL9.8File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted P...
CVE-2024-24496CRITICAL9.8An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,...
CVE-2024-24495CRITICAL9.8SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit...
CVE-2024-22836CRITICAL9.8An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc...
CVE-2024-0242CRITICAL9.8Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now