2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42576HIGH8.8A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attack...
CVE-2024-42564HIGH7.6ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/in...
CVE-2024-42561HIGH8.8Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number ...
CVE-2024-42557HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 all...
CVE-2024-42555HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 al...
CVE-2024-42554HIGH8.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type paramet...
CVE-2024-42553HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allo...
CVE-2024-42552HIGH8.6Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter...
CVE-2024-41700HIGH7.5Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41699HIGH7.5Priority – CWE-552: Files or Directories Accessible to External Parties
CVE-2024-41698HIGH7.5Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-28829HIGH7.8Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p...
CVE-2024-21689HIGH8This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9....
CVE-2024-43688HIGH7.3cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memo...
CVE-2024-7780HIGH7.2The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-7702HIGH7.2The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-38810HIGH7.5Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render sec...
CVE-2024-7949HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Online Graduate Tracer System up to 1.0. ...
CVE-2024-7944HIGH8.8A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Af...
CVE-2024-7827HIGH8.8The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_num...
CVE-2024-7943HIGH8.8A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue ...
CVE-2024-7305HIGH7.8A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write v...
CVE-2024-7931HIGH8.8A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue aff...
CVE-2024-7930HIGH8.8A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This ...
CVE-2024-7928HIGH7.5A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now