2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42603HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php...
CVE-2024-39690HIGH8.8Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner ca...
CVE-2024-42608HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.
CVE-2024-42006HIGH7.5Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
CVE-2024-34458HIGH7.5Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information d...
CVE-2024-6918HIGH7.5CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a ...
CVE-2024-42586HIGH8.8A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers t...
CVE-2024-42585HIGH8.8A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attacker...
CVE-2024-42584HIGH8.8A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attack...
CVE-2024-42583HIGH8.8A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers...
CVE-2024-42582HIGH8.8A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows atta...
CVE-2024-42581HIGH8.8A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attacker...
CVE-2024-42580HIGH8.8A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers ...
CVE-2024-42579HIGH8.8A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers t...
CVE-2024-42578HIGH8A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attacker...
CVE-2024-42577HIGH8.8A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers...
CVE-2024-42576HIGH8.8A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attack...
CVE-2024-42564HIGH7.6ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/in...
CVE-2024-42561HIGH8.8Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number ...
CVE-2024-42557HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 all...
CVE-2024-42555HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 al...
CVE-2024-42554HIGH8.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type paramet...
CVE-2024-42553HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allo...
CVE-2024-42552HIGH8.6Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter...
CVE-2024-41700HIGH7.5Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now