2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47057MEDIUM5.3SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. T...
CVE-2024-47055MEDIUM4.3SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vul...
CVE-2024-47056MEDIUM5.1SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be direct...
CVE-2024-51453HIGH7.5IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. A...
CVE-2024-38341HIGH7.5IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than...
CVE-2024-54020MEDIUM4.3A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allo...
CVE-2024-45094MEDIUM5.4IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerabilit...
CVE-2024-11185MEDIUM6.5On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly ...
CVE-2024-13966HIGH7.3ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged ...
CVE-2024-49197MEDIUM6.5An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1...
CVE-2024-49196HIGH7.5An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of...
CVE-2024-56193MEDIUM5.1There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local inform...
CVE-2024-47090MEDIUM6.1Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
CVE-2024-38866HIGH7.5Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
CVE-2024-13427MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-51102MEDIUM4.4PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51103MEDIUM6.5PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51099MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi...
CVE-2024-48704MEDIUM6.1Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter ...
CVE-2024-51360CRITICAL9.8An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor...
CVE-2024-51108MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL...
CVE-2024-51107MEDIUM4.8Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medi...
CVE-2024-51101CRITICAL9.8PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil...
CVE-2024-48702MEDIUM5.4PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-9163HIGH7.5A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now