2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38866 | HIGH | 7.5 | 0.3% | May 27, 2025 | Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection |
| CVE-2024-13427 | MEDIUM | 6.4 | 0.3% | May 24, 2025 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-51102 | MEDIUM | 4.4 | 0.2% | May 23, 2025 | PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili... |
| CVE-2024-51103 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili... |
| CVE-2024-51099 | MEDIUM | 6.1 | 0.3% | May 23, 2025 | A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi... |
| CVE-2024-48704 | MEDIUM | 6.1 | 0.2% | May 23, 2025 | Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter ... |
| CVE-2024-51360 | CRITICAL | 9.8 | 0.8% | May 23, 2025 | An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor... |
| CVE-2024-51108 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL... |
| CVE-2024-51107 | MEDIUM | 4.8 | 0.2% | May 23, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medi... |
| CVE-2024-51101 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil... |
| CVE-2024-48702 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter. |
| CVE-2024-9163 | HIGH | 7.5 | 0.4% | May 23, 2025 | A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.... |
| CVE-2024-7803 | HIGH | 7.5 | 0.5% | May 23, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2024-13945 | HIGH | 8.4 | 0.4% | May 23, 2025 | Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials becom... |
| CVE-2024-5962 | MEDIUM | 6.1 | 0.2% | May 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due... |
| CVE-2024-7487 | MEDIUM | 5.8 | 0.3% | May 22, 2025 | An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows ... |
| CVE-2024-7103 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7... |
| CVE-2024-6914 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re... |
| CVE-2024-51553 | HIGH | 7 | 0.3% | May 22, 2025 | Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator... |
| CVE-2024-51552 | HIGH | 7.1 | 0.3% | May 22, 2025 | Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ... |
| CVE-2024-48848 | HIGH | 7 | 0.3% | May 22, 2025 | Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat... |
| CVE-2024-41199 | HIGH | 7.2 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privile... |
| CVE-2024-41198 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges... |
| CVE-2024-41197 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege... |
| CVE-2024-41196 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now