2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47578 | CRITICAL | 9.1 | 0.9% | Dec 10, 2024 | Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web ... |
| CVE-2024-55638 | CRITICAL | 9.8 | 1.0% | Dec 10, 2024 | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f... |
| CVE-2024-55637 | CRITICAL | 9.8 | 0.8% | Dec 10, 2024 | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f... |
| CVE-2024-55636 | CRITICAL | 9.8 | 0.9% | Dec 10, 2024 | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f... |
| CVE-2024-46455 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser. |
| CVE-2024-53441 | CRITICAL | 9.1 | 0.3% | Dec 9, 2024 | An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping at... |
| CVE-2024-54934 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php. |
| CVE-2024-54932 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php. |
| CVE-2024-54931 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote... |
| CVE-2024-54925 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remot... |
| CVE-2024-54924 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote... |
| CVE-2024-54923 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which... |
| CVE-2024-54921 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote att... |
| CVE-2024-54918 | CRITICAL | 9.8 | 0.9% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.ph... |
| CVE-2024-48956 | CRITICAL | 9.8 | 0.9% | Dec 9, 2024 | Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially craft... |
| CVE-2024-40583 | CRITICAL | 9.1 | 0.6% | Dec 9, 2024 | Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials. |
| CVE-2024-54920 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which all... |
| CVE-2024-8259 | CRITICAL | 9.8 | 0.4% | Dec 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information ... |
| CVE-2024-53947 | CRITICAL | 9.8 | 0.8% | Dec 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. S... |
| CVE-2024-52480 | CRITICAL | 9.8 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in Astoundify Jobify jobify.This issue affects Jobify: from n/a through < 4.3.0. |
| CVE-2024-54215 | CRITICAL | 9.3 | 0.6% | Dec 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy.... |
| CVE-2024-53822 | CRITICAL | 10 | 0.7% | Dec 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Re... |
| CVE-2024-43222 | CRITICAL | 9.8 | 0.7% | Dec 9, 2024 | Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects ... |
| CVE-2024-55564 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow. |
| CVE-2024-12352 | CRITICAL | 9.8 | 0.7% | Dec 9, 2024 | A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affec... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now