2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-25309HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.p...
CVE-2024-25308HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.p...
CVE-2024-25306HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
CVE-2024-25305HIGH8.8Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a...
CVE-2024-25304HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
CVE-2024-25677HIGH8.8In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly ...
CVE-2024-23749HIGH7.8KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic...
CVE-2024-25004HIGH7.8KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf...
CVE-2024-25003HIGH7.8KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf...
CVE-2024-0229HIGH7.8An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a...
CVE-2024-0842HIGH7.5The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all version...
CVE-2024-24819HIGH8.8icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class...
CVE-2024-23639HIGH7.8Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM...
CVE-2024-24825HIGH7.5DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by an...
CVE-2024-24821HIGH7.8Composer is a dependency Manager for the PHP language. In affected versions several files within the local working direc...
CVE-2024-24820HIGH8.3Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configurat...
CVE-2024-24830HIGH8.8OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet...
CVE-2024-23756HIGH7.5The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated...
CVE-2024-23660HIGH7.5The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezo...
CVE-2024-1329HIGH7.5HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file wri...
CVE-2024-22795HIGH7Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privi...
CVE-2024-24113HIGH8.8xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control ex...
CVE-2024-0985HIGH8Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrar...
CVE-2024-23452HIGH7.5Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle re...
CVE-2024-25148HIGH8.1In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 be...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now