2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24004 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon... |
| CVE-2024-24002 | CRITICAL | 9.8 | 0.8% | Feb 7, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseRespons... |
| CVE-2024-24001 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRe... |
| CVE-2024-1284 | CRITICAL | 9.8 | 1.1% | Feb 7, 2024 | Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-1283 | CRITICAL | 9.8 | 1.5% | Feb 7, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit h... |
| CVE-2024-1264 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability... |
| CVE-2024-1263 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function ac... |
| CVE-2024-1262 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the... |
| CVE-2024-24577 | CRITICAL | 9.8 | 1.5% | Feb 6, 2024 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing... |
| CVE-2024-1261 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function... |
| CVE-2024-1260 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIn... |
| CVE-2024-1259 | CRITICAL | 9.8 | 0.7% | Feb 6, 2024 | A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some ... |
| CVE-2024-1252 | CRITICAL | 9.8 | 0.7% | Feb 6, 2024 | A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unkn... |
| CVE-2024-24015 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset... |
| CVE-2024-24013 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l... |
| CVE-2024-24000 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the upl... |
| CVE-2024-1251 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of ... |
| CVE-2024-24592 | CRITICAL | 9.8 | 1.0% | Feb 6, 2024 | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta... |
| CVE-2024-23917 | CRITICAL | 9.8 | 53.7% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible |
| CVE-2024-25140 | CRITICAL | 9.8 | 0.5% | Feb 6, 2024 | A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Au... |
| CVE-2024-22433 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSetti... |
| CVE-2024-22853 | CRITICAL | 9.8 | 4.8% | Feb 6, 2024 | D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote a... |
| CVE-2024-22852 | CRITICAL | 9.8 | 1.1% | Feb 6, 2024 | D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vu... |
| CVE-2024-24112 | CRITICAL | 9.8 | 3.3% | Feb 6, 2024 | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. |
| CVE-2024-0244 | CRITICAL | 9.8 | 1.4% | Feb 6, 2024 | Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now