2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10609 | CRITICAL | 9.8 | 0.5% | Nov 1, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. Th... |
| CVE-2024-10608 | CRITICAL | 9.8 | 0.7% | Nov 1, 2024 | A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affe... |
| CVE-2024-10607 | CRITICAL | 9.8 | 0.7% | Nov 1, 2024 | A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnera... |
| CVE-2024-10602 | CRITICAL | 9.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknow... |
| CVE-2024-10601 | CRITICAL | 9.8 | 0.5% | Oct 31, 2024 | A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability ... |
| CVE-2024-10600 | CRITICAL | 9.8 | 6.3% | Oct 31, 2024 | A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown functi... |
| CVE-2024-10597 | CRITICAL | 9.8 | 0.6% | Oct 31, 2024 | A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of th... |
| CVE-2024-10595 | CRITICAL | 9.8 | 0.6% | Oct 31, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the fun... |
| CVE-2024-48359 | CRITICAL | 9.8 | 2.2% | Oct 31, 2024 | Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame... |
| CVE-2024-51065 | CRITICAL | 9.8 | 0.5% | Oct 31, 2024 | Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username ... |
| CVE-2024-51064 | CRITICAL | 9.8 | 0.6% | Oct 31, 2024 | Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.... |
| CVE-2024-51063 | CRITICAL | 9.1 | 0.5% | Oct 31, 2024 | Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile numbe... |
| CVE-2024-51060 | CRITICAL | 9.1 | 0.5% | Oct 31, 2024 | Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter. |
| CVE-2024-42515 | CRITICAL | 9.9 | 0.5% | Oct 31, 2024 | Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special... |
| CVE-2024-39332 | CRITICAL | 9.8 | 1.2% | Oct 31, 2024 | Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading ... |
| CVE-2024-51482 | CRITICAL | 9.9 | 36.9% | Oct 31, 2024 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulne... |
| CVE-2024-51478 | CRITICAL | 9.1 | 0.4% | Oct 31, 2024 | YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt... |
| CVE-2024-51260 | CRITICAL | 9.8 | 0.6% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-51255 | CRITICAL | 9.8 | 0.4% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-48910 | CRITICAL | 9.8 | 1.2% | Oct 31, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to p... |
| CVE-2024-51259 | CRITICAL | 9.8 | 0.3% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-42835 | CRITICAL | 9.8 | 1.0% | Oct 31, 2024 | langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component. |
| CVE-2024-49674 | CRITICAL | 9.6 | 0.2% | Oct 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Uploa... |
| CVE-2024-10392 | CRITICAL | 9.8 | 13.1% | Oct 31, 2024 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val... |
| CVE-2024-10561 | CRITICAL | 9.8 | 0.8% | Oct 31, 2024 | A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now