2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25100 | CRITICAL | 9.8 | 0.8% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue ... |
| CVE-2024-25722 | CRITICAL | 9.8 | 0.6% | Feb 11, 2024 | qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection. |
| CVE-2024-25718 | CRITICAL | 9.8 | 0.7% | Feb 11, 2024 | In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which int... |
| CVE-2024-25714 | CRITICAL | 9.8 | 0.8% | Feb 11, 2024 | In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attack... |
| CVE-2024-23724 | CRITICAL | 9 | 3.5% | Feb 11, 2024 | Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any acco... |
| CVE-2024-25316 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?... |
| CVE-2024-25315 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2... |
| CVE-2024-25314 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2. |
| CVE-2024-25307 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/boo... |
| CVE-2024-25302 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter. |
| CVE-2024-25678 | CRITICAL | 9.8 | 0.4% | Feb 9, 2024 | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled. |
| CVE-2024-25675 | CRITICAL | 9.8 | 0.8% | Feb 9, 2024 | An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process... |
| CVE-2024-25674 | CRITICAL | 9.8 | 0.8% | Feb 9, 2024 | An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the... |
| CVE-2024-21762 | CRITICAL | 9.8 | 84.3% | Feb 9, 2024 | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0... |
| CVE-2024-24308 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows re... |
| CVE-2024-1353 | CRITICAL | 9.8 | 0.7% | Feb 9, 2024 | A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the fun... |
| CVE-2024-24393 | CRITICAL | 9.8 | 1.2% | Feb 8, 2024 | File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted P... |
| CVE-2024-24496 | CRITICAL | 9.8 | 19.5% | Feb 8, 2024 | An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,... |
| CVE-2024-24495 | CRITICAL | 9.8 | 1.3% | Feb 8, 2024 | SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit... |
| CVE-2024-22836 | CRITICAL | 9.8 | 30.0% | Feb 8, 2024 | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc... |
| CVE-2024-0242 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access ... |
| CVE-2024-24321 | CRITICAL | 9.8 | 2.4% | Feb 8, 2024 | An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 pa... |
| CVE-2024-24213 | CRITICAL | 9.8 | 0.8% | Feb 8, 2024 | Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/que... |
| CVE-2024-25191 | CRITICAL | 9.8 | 0.9% | Feb 8, 2024 | php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent... |
| CVE-2024-25190 | CRITICAL | 9.8 | 0.9% | Feb 8, 2024 | l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now