2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54924CRITICAL9.8A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote...
CVE-2024-54923CRITICAL9.8A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which...
CVE-2024-54921CRITICAL9.8A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote att...
CVE-2024-54918CRITICAL9.8Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.ph...
CVE-2024-54147MEDIUM6.8Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not valid...
CVE-2024-53847MEDIUM5.1The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS...
CVE-2024-52599MEDIUM5.4Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi...
CVE-2024-52586HIGH7.8eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version ...
CVE-2024-48956CRITICAL9.8Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially craft...
CVE-2024-46547HIGH7.5A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized...
CVE-2024-12057LOW1.8User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a W...
CVE-2024-54935MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learn...
CVE-2024-54933HIGH7.2Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
CVE-2024-54930HIGH7.2Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
CVE-2024-54922HIGH7.2A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote at...
CVE-2024-11608HIGH7.8A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow....
CVE-2024-11454HIGH7.8A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and ...
CVE-2024-11268MEDIUM5.5A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor c...
CVE-2024-54926HIGH8.8A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allow...
CVE-2024-53450HIGH7.5RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents...
CVE-2024-45761HIGH8.1Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. ...
CVE-2024-45760HIGH8.8Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A ...
CVE-2024-40583CRITICAL9.1Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
CVE-2024-40582HIGH7.5Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
CVE-2024-54920CRITICAL9.8A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now