2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9672MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute special...
CVE-2024-55638CRITICAL9.8Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f...
CVE-2024-55637CRITICAL9.8Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f...
CVE-2024-55636CRITICAL9.8Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f...
CVE-2024-55635MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core...
CVE-2024-55634HIGH8.1A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fr...
CVE-2024-12393MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core...
CVE-2024-55601MEDIUM5.3Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markd...
CVE-2024-50628HIGH8.8An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local ar...
CVE-2024-50627HIGH8.8An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file u...
CVE-2024-50626HIGH8.8An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This...
CVE-2024-50625HIGH8An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web appl...
CVE-2024-12174LOW2.7An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at...
CVE-2024-54151HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to...
CVE-2024-54149HIGH8.4Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to ve...
CVE-2024-46455CRITICAL9.8unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
CVE-2024-12369MEDIUM4.2A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc...
CVE-2024-53441CRITICAL9.1An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping at...
CVE-2024-54938HIGH7.5A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to acc...
CVE-2024-54934CRITICAL9.8Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
CVE-2024-54932CRITICAL9.8Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
CVE-2024-54931CRITICAL9.8A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote...
CVE-2024-54928HIGH7.2kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,
CVE-2024-54927HIGH7.2Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.
CVE-2024-54925CRITICAL9.8A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remot...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now