2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51327CRITICAL9.8SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authent...
CVE-2024-51326HIGH7.5SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrar...
CVE-2024-51127HIGH7.1An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensit...
CVE-2024-48336HIGH8.4The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app b...
CVE-2024-34887MEDIUM4.9Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administr...
CVE-2024-34883MEDIUM4.9Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators...
CVE-2024-34882MEDIUM4.9Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato...
CVE-2024-10766CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1...
CVE-2024-51136CRITICAL9.8An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive informat...
CVE-2024-48809HIGH7.5An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a ...
CVE-2024-10765CRITICAL9.8A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerab...
CVE-2024-10764CRITICAL9.8A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects a...
CVE-2024-51685MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gan...
CVE-2024-51683MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Custom pos...
CVE-2024-51682MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Build...
CVE-2024-51681MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP ...
CVE-2024-51680MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Cres...
CVE-2024-51678MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rat...
CVE-2024-51677MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Bas...
CVE-2024-51626HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom...
CVE-2024-45893HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45891HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45890HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when ...
CVE-2024-45889HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45888HIGH8DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now