2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-44662MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
CVE-2024-44660MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters...
CVE-2024-44658MEDIUM6.5PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in...
CVE-2024-44655MEDIUM6.1PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-...
CVE-2024-44654MEDIUM6.5PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset...
CVE-2024-44657MEDIUM6.5PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in betw...
CVE-2024-44653MEDIUM6.5Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.
CVE-2024-44651MEDIUM6.5Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover....
CVE-2024-46336MEDIUM6.1kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
CVE-2024-46334MEDIUM6.1kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword par...
CVE-2024-44652MEDIUM6.5Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastna...
CVE-2024-44648MEDIUM6.5PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
CVE-2024-44647MEDIUM6.1PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.
CVE-2024-44644MEDIUM6.5PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
CVE-2024-44641MEDIUM6.5PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
CVE-2024-55016MEDIUM6.5PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in lo...
CVE-2024-44640MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parame...
CVE-2024-44639MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short pa...
CVE-2024-44636MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin...
CVE-2024-44635MEDIUM6.1PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters ...
CVE-2024-44633MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-passwor...
CVE-2024-44632MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recov...
CVE-2024-44630MEDIUM6.5Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These incl...
CVE-2024-42749MEDIUM6.1Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted ...
CVE-2024-21635HIGH7.5Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. Wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now