2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48581 | CRITICAL | 9.8 | 1.1% | Oct 25, 2024 | File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary c... |
| CVE-2024-48580 | CRITICAL | 9.8 | 0.9% | Oct 25, 2024 | SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary... |
| CVE-2024-48579 | CRITICAL | 9.8 | 0.9% | Oct 25, 2024 | SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to exec... |
| CVE-2024-48204 | CRITICAL | 9.8 | 0.8% | Oct 25, 2024 | SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary... |
| CVE-2024-48428 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function. |
| CVE-2024-49753 | CRITICAL | 9.1 | 0.6% | Oct 25, 2024 | Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.... |
| CVE-2024-10381 | CRITICAL | 9.8 | 0.8% | Oct 25, 2024 | This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management... |
| CVE-2024-10378 | CRITICAL | 9.8 | 0.5% | Oct 25, 2024 | A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile... |
| CVE-2024-10377 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDe... |
| CVE-2024-10376 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function a... |
| CVE-2024-9302 | CRITICAL | 9.8 | 0.6% | Oct 25, 2024 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalat... |
| CVE-2024-47406 | CRITICAL | 9.8 | 0.6% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulner... |
| CVE-2024-9488 | CRITICAL | 9.8 | 0.8% | Oct 25, 2024 | The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including... |
| CVE-2024-10371 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the ... |
| CVE-2024-10370 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue... |
| CVE-2024-10369 | CRITICAL | 9.8 | 0.8% | Oct 25, 2024 | A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vu... |
| CVE-2024-10368 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an un... |
| CVE-2024-10350 | CRITICAL | 9.8 | 0.5% | Oct 24, 2024 | A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulner... |
| CVE-2024-41618 | CRITICAL | 9.8 | 0.5% | Oct 24, 2024 | Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` fu... |
| CVE-2024-41617 | CRITICAL | 9.8 | 1.1% | Oct 24, 2024 | Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_log... |
| CVE-2024-10349 | CRITICAL | 9.8 | 0.6% | Oct 24, 2024 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected... |
| CVE-2024-47883 | CRITICAL | 9.1 | 1.6% | Oct 24, 2024 | The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework u... |
| CVE-2024-48145 | CRITICAL | 9.1 | 0.5% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to a... |
| CVE-2024-48144 | CRITICAL | 9.1 | 0.5% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attacke... |
| CVE-2024-48143 | CRITICAL | 9.1 | 0.4% | Oct 24, 2024 | A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now