2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48283 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-res... |
| CVE-2024-9976 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u... |
| CVE-2024-49388 | CRITICAL | 9.1 | 0.3% | Oct 15, 2024 | Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro... |
| CVE-2024-45275 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker ... |
| CVE-2024-45274 | CRITICAL | 9.8 | 1.5% | Oct 15, 2024 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. |
| CVE-2024-9974 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ... |
| CVE-2024-9973 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an ... |
| CVE-2024-47945 | CRITICAL | 9.8 | 0.9% | Oct 15, 2024 | The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The... |
| CVE-2024-9985 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privil... |
| CVE-2024-9984 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re... |
| CVE-2024-9925 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow... |
| CVE-2024-47943 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices c... |
| CVE-2024-9982 | CRITICAL | 9.8 | 0.7% | Oct 15, 2024 | AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Cam... |
| CVE-2024-9972 | CRITICAL | 9.8 | 0.7% | Oct 15, 2024 | Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to... |
| CVE-2024-48823 | CRITICAL | 9.8 | 0.5% | Oct 14, 2024 | Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r... |
| CVE-2024-48168 | CRITICAL | 9.8 | 0.9% | Oct 14, 2024 | A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a... |
| CVE-2024-46535 | CRITICAL | 9.8 | 0.4% | Oct 14, 2024 | Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUser... |
| CVE-2024-48153 | CRITICAL | 9.8 | 0.7% | Oct 14, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-48150 | CRITICAL | 9.8 | 0.7% | Oct 14, 2024 | D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function. |
| CVE-2024-48257 | CRITICAL | 9.8 | 0.6% | Oct 14, 2024 | Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin. |
| CVE-2024-48251 | CRITICAL | 9.8 | 0.5% | Oct 14, 2024 | Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. |
| CVE-2024-48255 | CRITICAL | 9.8 | 0.4% | Oct 14, 2024 | Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. |
| CVE-2024-48253 | CRITICAL | 9.8 | 0.4% | Oct 14, 2024 | Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. |
| CVE-2024-9137 | CRITICAL | 9.4 | 0.5% | Oct 14, 2024 | The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner... |
| CVE-2024-9924 | CRITICAL | 9.8 | 0.8% | Oct 14, 2024 | The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now