2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21215HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2024-21214HIGH8.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versi...
CVE-2024-21195HIGH7.6Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions ...
CVE-2024-21191HIGH7.6Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component:...
CVE-2024-21190HIGH7.5Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cl...
CVE-2024-41344HIGH7.5A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator passw...
CVE-2024-35584HIGH8.8SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL...
CVE-2024-5749HIGH7.5Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
CVE-2024-48915HIGH8.7Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, cer...
CVE-2024-47876HIGH8.8Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea...
CVE-2024-47874HIGH8.7Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treat...
CVE-2024-47824HIGH8.7matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starti...
CVE-2024-47779HIGH7Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a ...
CVE-2024-47771HIGH7Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vul...
CVE-2024-47080HIGH8.7matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t...
CVE-2024-48282HIGH7.6A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Manag...
CVE-2024-48280HIGH7.6A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Managemen...
CVE-2024-48279HIGH7.6A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Manageme...
CVE-2024-9975HIGH8.8A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t...
CVE-2024-49387HIGH7.5Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis ...
CVE-2024-45276HIGH7.5An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
CVE-2024-45273HIGH7.8An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak ...
CVE-2024-45272HIGH7.5An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with...
CVE-2024-45271HIGH7.8An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
CVE-2024-9983HIGH7.5Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now