2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-37143CRITICAL9.8Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8....
CVE-2024-53552CRITICAL9.8CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
CVE-2024-47578CRITICAL9.1Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web ...
CVE-2024-55638CRITICAL9.8Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f...
CVE-2024-55637CRITICAL9.8Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f...
CVE-2024-55636CRITICAL9.8Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f...
CVE-2024-46455CRITICAL9.8unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
CVE-2024-53441CRITICAL9.1An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping at...
CVE-2024-54934CRITICAL9.8Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
CVE-2024-54932CRITICAL9.8Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
CVE-2024-54931CRITICAL9.8A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote...
CVE-2024-54925CRITICAL9.8A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remot...
CVE-2024-54924CRITICAL9.8A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote...
CVE-2024-54923CRITICAL9.8A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which...
CVE-2024-54921CRITICAL9.8A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote att...
CVE-2024-54918CRITICAL9.8Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.ph...
CVE-2024-48956CRITICAL9.8Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially craft...
CVE-2024-40583CRITICAL9.1Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
CVE-2024-54920CRITICAL9.8A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which all...
CVE-2024-8259CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information ...
CVE-2024-53947CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. S...
CVE-2024-52480CRITICAL9.8Missing Authorization vulnerability in Astoundify Jobify jobify.This issue affects Jobify: from n/a through < 4.3.0.
CVE-2024-54215CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy....
CVE-2024-53822CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Re...
CVE-2024-43222CRITICAL9.8Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now