2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38866HIGH7.5Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
CVE-2024-13427MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-51102MEDIUM4.4PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51103MEDIUM6.5PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51099MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi...
CVE-2024-48704MEDIUM6.1Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter ...
CVE-2024-51360CRITICAL9.8An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor...
CVE-2024-51108MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL...
CVE-2024-51107MEDIUM4.8Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medi...
CVE-2024-51101CRITICAL9.8PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil...
CVE-2024-48702MEDIUM5.4PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-9163HIGH7.5A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11....
CVE-2024-7803HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2024-13945HIGH8.4Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials becom...
CVE-2024-5962MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due...
CVE-2024-7487MEDIUM5.8An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows ...
CVE-2024-7103MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7...
CVE-2024-6914CRITICAL9.8An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re...
CVE-2024-51553HIGH7Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator...
CVE-2024-51552HIGH7.1Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ...
CVE-2024-48848HIGH7Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat...
CVE-2024-41199HIGH7.2An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privile...
CVE-2024-41198CRITICAL9.8An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges...
CVE-2024-41197CRITICAL9.8An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege...
CVE-2024-41196CRITICAL9.8An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now