2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49071MEDIUM6.5Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender al...
CVE-2024-55662HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0,...
CVE-2024-54810CRITICAL9.8A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment Sy...
CVE-2024-47238MEDIUM6.7Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi...
CVE-2024-31670MEDIUM6.3rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf f...
CVE-2024-55099CRITICAL9.8A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows ...
CVE-2024-52901MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to impro...
CVE-2024-55633MEDIUM6.5Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c...
CVE-2024-54842CRITICAL9.8A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php vi...
CVE-2024-21575CRITICAL9.2ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` fie...
CVE-2024-50584MEDIUM4.4An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i...
CVE-2024-28146HIGH8.4The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware d...
CVE-2024-28145MEDIUM5.9An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici...
CVE-2024-28144MEDIUM5.5An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaw...
CVE-2024-28143HIGH8.4The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vu...
CVE-2024-54122MEDIUM4.7Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may...
CVE-2024-54119HIGH7.5Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability...
CVE-2024-54118Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-47947MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-36498MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-36494MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-28142MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-12271MEDIUM4.4The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in a...
CVE-2024-9387MEDIUM6.4An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 bef...
CVE-2024-9367MEDIUM4.3An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now