2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25189 | CRITICAL | 9.8 | 1.0% | Feb 8, 2024 | libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent... |
| CVE-2024-1207 | CRITICAL | 9.8 | 3.2% | Feb 8, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmy... |
| CVE-2024-24216 | CRITICAL | 9.8 | 1.3% | Feb 8, 2024 | Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection met... |
| CVE-2024-24091 | CRITICAL | 9.8 | 1.1% | Feb 8, 2024 | Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file up... |
| CVE-2024-24202 | CRITICAL | 9.8 | 1.0% | Feb 8, 2024 | An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and... |
| CVE-2024-24021 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ... |
| CVE-2024-24017 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l... |
| CVE-2024-24014 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l... |
| CVE-2024-24003 | CRITICAL | 9.8 | 0.8% | Feb 8, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon... |
| CVE-2024-22394 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific con... |
| CVE-2024-24026 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controll... |
| CVE-2024-24025 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileCo... |
| CVE-2024-24024 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.File... |
| CVE-2024-24023 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ... |
| CVE-2024-24018 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset... |
| CVE-2024-24822 | CRITICAL | 9.1 | 0.5% | Feb 7, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can cr... |
| CVE-2024-24563 | CRITICAL | 9.8 | 1.5% | Feb 7, 2024 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, w... |
| CVE-2024-24811 | CRITICAL | 9.8 | 0.9% | Feb 7, 2024 | SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut... |
| CVE-2024-24189 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c. |
| CVE-2024-24188 | CRITICAL | 9.8 | 0.8% | Feb 7, 2024 | Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c. |
| CVE-2024-24186 | CRITICAL | 9.8 | 0.9% | Feb 7, 2024 | Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish... |
| CVE-2024-24133 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. |
| CVE-2024-24303 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before versio... |
| CVE-2024-1268 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unk... |
| CVE-2024-24019 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now