2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47080HIGH8.7matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t...
CVE-2024-9979MEDIUM5.3A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or ...
CVE-2024-48948MEDIUM4.8The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if t...
CVE-2024-9986CRITICAL9.8A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a...
CVE-2024-9977MEDIUM5.1A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected ...
CVE-2024-48283CRITICAL9.8Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-res...
CVE-2024-48282HIGH7.6A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Manag...
CVE-2024-48280HIGH7.6A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Managemen...
CVE-2024-48279HIGH7.6A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Manageme...
CVE-2024-48278MEDIUM5.5Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) v...
CVE-2024-9976CRITICAL9.8A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u...
CVE-2024-9975HIGH8.8A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t...
CVE-2024-49388CRITICAL9.1Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro...
CVE-2024-49387HIGH7.5Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis ...
CVE-2024-49384MEDIUM4.3Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products ...
CVE-2024-49383MEDIUM4.3Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products a...
CVE-2024-49382MEDIUM4.3Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products ...
CVE-2024-47674MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in er...
CVE-2024-45276HIGH7.5An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
CVE-2024-45275CRITICAL9.8The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker ...
CVE-2024-45274CRITICAL9.8An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
CVE-2024-45273HIGH7.8An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak ...
CVE-2024-45272HIGH7.5An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with...
CVE-2024-45271HIGH7.8An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
CVE-2024-9974CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now