2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51327 | CRITICAL | 9.8 | 0.8% | Nov 4, 2024 | SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authent... |
| CVE-2024-51326 | HIGH | 7.5 | 0.9% | Nov 4, 2024 | SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrar... |
| CVE-2024-51127 | HIGH | 7.1 | 0.7% | Nov 4, 2024 | An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensit... |
| CVE-2024-48336 | HIGH | 8.4 | 0.5% | Nov 4, 2024 | The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app b... |
| CVE-2024-34887 | MEDIUM | 4.9 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administr... |
| CVE-2024-34883 | MEDIUM | 4.9 | 0.4% | Nov 4, 2024 | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators... |
| CVE-2024-34882 | MEDIUM | 4.9 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato... |
| CVE-2024-10766 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1... |
| CVE-2024-51136 | CRITICAL | 9.8 | 1.2% | Nov 4, 2024 | An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive informat... |
| CVE-2024-48809 | HIGH | 7.5 | 0.6% | Nov 4, 2024 | An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a ... |
| CVE-2024-10765 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerab... |
| CVE-2024-10764 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects a... |
| CVE-2024-51685 | MEDIUM | 4.8 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gan... |
| CVE-2024-51683 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Custom pos... |
| CVE-2024-51682 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Build... |
| CVE-2024-51681 | MEDIUM | 5.4 | 0.3% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP ... |
| CVE-2024-51680 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Cres... |
| CVE-2024-51678 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rat... |
| CVE-2024-51677 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Bas... |
| CVE-2024-51626 | HIGH | 8.8 | 0.4% | Nov 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom... |
| CVE-2024-45893 | HIGH | 8 | 1.6% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45891 | HIGH | 8 | 1.3% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45890 | HIGH | 8 | 2.1% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when ... |
| CVE-2024-45889 | HIGH | 8 | 1.6% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45888 | HIGH | 8 | 2.0% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now