2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55878MEDIUM6.8SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to ve...
CVE-2024-55877HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5...
CVE-2024-55876MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0,...
CVE-2024-55875CRITICAL9.8http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex...
CVE-2024-55663CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc...
CVE-2024-54811CRITICAL9.8A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to ex...
CVE-2024-49147CRITICAL9.8Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on t...
CVE-2024-49071MEDIUM6.5Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender al...
CVE-2024-55662HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0,...
CVE-2024-54810CRITICAL9.8A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment Sy...
CVE-2024-47238MEDIUM6.7Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi...
CVE-2024-31670MEDIUM6.3rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf f...
CVE-2024-55099CRITICAL9.8A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows ...
CVE-2024-52901MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to impro...
CVE-2024-55633MEDIUM6.5Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c...
CVE-2024-54842CRITICAL9.8A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php vi...
CVE-2024-21575CRITICAL9.2ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` fie...
CVE-2024-50584MEDIUM4.4An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i...
CVE-2024-28146HIGH8.4The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware d...
CVE-2024-28145MEDIUM5.9An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici...
CVE-2024-28144MEDIUM5.5An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaw...
CVE-2024-28143HIGH8.4The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vu...
CVE-2024-54122MEDIUM4.7Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may...
CVE-2024-54119HIGH7.5Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability...
CVE-2024-54118——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now