2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51065 | CRITICAL | 9.8 | 0.5% | Oct 31, 2024 | Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username ... |
| CVE-2024-51064 | CRITICAL | 9.8 | 0.6% | Oct 31, 2024 | Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.... |
| CVE-2024-51063 | CRITICAL | 9.1 | 0.5% | Oct 31, 2024 | Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile numbe... |
| CVE-2024-51060 | CRITICAL | 9.1 | 0.5% | Oct 31, 2024 | Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter. |
| CVE-2024-50802 | MEDIUM | 6 | 0.4% | Oct 31, 2024 | A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle... |
| CVE-2024-50801 | MEDIUM | 6 | 0.4% | Oct 31, 2024 | A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle... |
| CVE-2024-48200 | HIGH | 8.4 | 0.2% | Oct 31, 2024 | An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove fun... |
| CVE-2024-42515 | CRITICAL | 9.9 | 0.5% | Oct 31, 2024 | Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special... |
| CVE-2024-39332 | CRITICAL | 9.8 | 1.2% | Oct 31, 2024 | Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading ... |
| CVE-2024-10573 | MEDIUM | 6.7 | 0.3% | Oct 31, 2024 | An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may writ... |
| CVE-2024-51482 | CRITICAL | 9.9 | 36.9% | Oct 31, 2024 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulne... |
| CVE-2024-50356 | NONE | 0 | 0.4% | Oct 31, 2024 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-... |
| CVE-2024-50347 | MEDIUM | 6.3 | 0.3% | Oct 31, 2024 | Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is a... |
| CVE-2024-7883 | LOW | 3.7 | 0.5% | Oct 31, 2024 | When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floatin... |
| CVE-2024-51481 | LOW | 1 | 0.2% | Oct 31, 2024 | Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, expo... |
| CVE-2024-51478 | CRITICAL | 9.1 | 0.4% | Oct 31, 2024 | YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt... |
| CVE-2024-51430 | MEDIUM | 6.4 | 0.5% | Oct 31, 2024 | Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker t... |
| CVE-2024-8185 | HIGH | 7.5 | 0.5% | Oct 31, 2024 | Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a den... |
| CVE-2024-51260 | CRITICAL | 9.8 | 0.6% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-51255 | CRITICAL | 9.8 | 0.4% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-50354 | MEDIUM | 5.5 | 0.3% | Oct 31, 2024 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deseriali... |
| CVE-2024-8553 | MEDIUM | 6.3 | 0.4% | Oct 31, 2024 | A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authent... |
| CVE-2024-48910 | CRITICAL | 9.8 | 1.2% | Oct 31, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to p... |
| CVE-2024-51259 | CRITICAL | 9.8 | 0.3% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-51254 | HIGH | 8.8 | 0.4% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now