2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-44647MEDIUM6.1PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.
CVE-2024-44644MEDIUM6.5PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
CVE-2024-44641MEDIUM6.5PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
CVE-2024-55016MEDIUM6.5PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in lo...
CVE-2024-44640MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parame...
CVE-2024-44639MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short pa...
CVE-2024-44636MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin...
CVE-2024-44635MEDIUM6.1PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters ...
CVE-2024-44633MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-passwor...
CVE-2024-44632MEDIUM6.5PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recov...
CVE-2024-44630MEDIUM6.5Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These incl...
CVE-2024-42749MEDIUM6.1Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted ...
CVE-2024-21635HIGH7.5Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. Wh...
CVE-2024-9126HIGH7.5Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a use...
CVE-2024-7021MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to...
CVE-2024-7017HIGH7.5Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potential...
CVE-2024-13983MEDIUM6.3Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform...
CVE-2024-13178MEDIUM4.3Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform ...
CVE-2024-11920MEDIUM4.3Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform...
CVE-2024-11919MEDIUM4.3Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to ...
CVE-2024-48829MEDIUM6.7Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Inj...
CVE-2024-47866HIGH7.5Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argume...
CVE-2024-45301MEDIUM5.3Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can c...
CVE-2024-32014MEDIUM4.7A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...
CVE-2024-32011HIGH8.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now