2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-44587HIGH8.8itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
CVE-2024-8470HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j...
CVE-2024-8469HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport...
CVE-2024-8468HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /job...
CVE-2024-8467HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport...
CVE-2024-8466HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j...
CVE-2024-8465HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jo...
CVE-2024-8464HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /j...
CVE-2024-8463HIGH8.8File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an auth...
CVE-2024-7884HIGH7.5When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the calle...
CVE-2024-5957HIGH7.5This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
CVE-2024-8178HIGH8.8The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it...
CVE-2024-45063HIGH8.8The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished p...
CVE-2024-43110HIGH8.8The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software runni...
CVE-2024-42416HIGH8.8The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbit...
CVE-2024-32668HIGH8.2An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controll...
CVE-2024-45288HIGH8.4A missing null-termination character in the last element of an nvlist array string can lead to writing outside the alloc...
CVE-2024-45287HIGH7.5A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a s...
CVE-2024-41928HIGH8.4Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bh...
CVE-2024-7627HIGH8.1The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'check...
CVE-2024-45692HIGH7.5Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
CVE-2024-20505HIGH7.5A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x...
CVE-2024-45395HIGH7.5sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in version...
CVE-2024-44999HIGH7.1In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot...
CVE-2024-44998HIGH7.8In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now