2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7835HIGH8.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Infor...
CVE-2024-7735CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics ...
CVE-2024-46544MEDIUM5.9Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem...
CVE-2024-8903MEDIUM4.7Local active protection service settings manipulation due to unnecessary privileges assignment. The following products a...
CVE-2024-45348HIGH8.8Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack ...
CVE-2024-8606HIGH8.8Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass...
CVE-2024-8758MEDIUM4.8The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which...
CVE-2024-7846MEDIUM5.4YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied bloc...
CVE-2024-47227MEDIUM6.1iRedAdmin before 2.6 allows XSS, e.g., via order_name.
CVE-2024-9094CRITICAL9.8A vulnerability classified as critical was found in code-projects Blood Bank System 1.0. This vulnerability affects unkn...
CVE-2024-9093HIGH7.2A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0....
CVE-2024-9092MEDIUM6.1A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble...
CVE-2024-45453LOW3.7Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This i...
CVE-2024-44048MEDIUM6.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-43996MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit ...
CVE-2024-9091CRITICAL9.8A vulnerability was found in code-projects Student Record System 1.0. It has been declared as critical. Affected by this...
CVE-2024-9090CRITICAL9.8A vulnerability was found in SourceCodester Modern Loan Management System 1.0. It has been classified as critical. Affec...
CVE-2024-9089MEDIUM5.4A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue ...
CVE-2024-43989HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects J...
CVE-2024-9088CRITICAL9.8A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This ...
CVE-2024-9087CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an un...
CVE-2024-9086CRITICAL9.8A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an...
CVE-2024-40703MEDIUM5.5IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Re...
CVE-2024-9084MEDIUM5.4A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u...
CVE-2024-9083MEDIUM4.8A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now