2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47856CRITICAL9.8In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the...
CVE-2024-14007HIGH8.7Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions ...
CVE-2024-14015HIGH7.1The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputtin...
CVE-2024-21923HIGH7.3Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially result...
CVE-2024-21922HIGH7.3A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resul...
CVE-2024-31405——Rejected reason: Voluntarily withdrawn
CVE-2024-8528MEDIUM5.4Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload d...
CVE-2024-8527HIGH8.6Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may all...
CVE-2024-44664MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and ...
CVE-2024-44661MEDIUM5.4PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart....
CVE-2024-44659CRITICAL9.8PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
CVE-2024-46335MEDIUM4.6PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parame...
CVE-2024-44663MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
CVE-2024-44662MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
CVE-2024-44660MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters...
CVE-2024-44658MEDIUM6.5PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in...
CVE-2024-44655MEDIUM6.1PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-...
CVE-2024-44654MEDIUM6.5PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset...
CVE-2024-44657MEDIUM6.5PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in betw...
CVE-2024-44653MEDIUM6.5Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.
CVE-2024-44651MEDIUM6.5Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover....
CVE-2024-46336MEDIUM6.1kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
CVE-2024-46334MEDIUM6.1kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword par...
CVE-2024-44652MEDIUM6.5Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastna...
CVE-2024-44648MEDIUM6.5PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now