2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-10609CRITICAL9.8A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. Th...
CVE-2024-10608CRITICAL9.8A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affe...
CVE-2024-10607CRITICAL9.8A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnera...
CVE-2024-10602CRITICAL9.8A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknow...
CVE-2024-10601CRITICAL9.8A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability ...
CVE-2024-10600CRITICAL9.8A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown functi...
CVE-2024-10597CRITICAL9.8A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of th...
CVE-2024-10595CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the fun...
CVE-2024-48359CRITICAL9.8Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame...
CVE-2024-51065CRITICAL9.8Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username ...
CVE-2024-51064CRITICAL9.8Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries....
CVE-2024-51063CRITICAL9.1Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile numbe...
CVE-2024-51060CRITICAL9.1Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.
CVE-2024-42515CRITICAL9.9Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special...
CVE-2024-39332CRITICAL9.8Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading ...
CVE-2024-51482CRITICAL9.9ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulne...
CVE-2024-51478CRITICAL9.1YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt...
CVE-2024-51260CRITICAL9.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-51255CRITICAL9.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-48910CRITICAL9.8DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to p...
CVE-2024-51259CRITICAL9.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-42835CRITICAL9.8langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
CVE-2024-49674CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Uploa...
CVE-2024-10392CRITICAL9.8The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val...
CVE-2024-10561CRITICAL9.8A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now