2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6672HIGH8.8In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged ...
CVE-2024-6671CRITICAL9.8In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injec...
CVE-2024-6670CRITICAL9.8In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to r...
CVE-2024-45302HIGH7.8RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu...
CVE-2024-2502LOW2An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occu...
CVE-2024-41349MEDIUM6.1unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.
CVE-2024-41372CRITICAL9.8Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.
CVE-2024-41371MEDIUM6.1Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
CVE-2024-41370CRITICAL9.8Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
CVE-2024-41369CRITICAL9.8RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php
CVE-2024-41368CRITICAL9.8RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMa...
CVE-2024-41367CRITICAL9.8RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\ap...
CVE-2024-41366CRITICAL9.8RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
CVE-2024-41364CRITICAL9.8RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
CVE-2024-41361CRITICAL9.8RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFold...
CVE-2024-41358MEDIUM6.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
CVE-2024-41351MEDIUM6.1bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php
CVE-2024-41350MEDIUM6.1bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php
CVE-2024-41348MEDIUM6.1openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php
CVE-2024-41347MEDIUM6.1openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php
CVE-2024-41346MEDIUM5.4openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php
CVE-2024-41345MEDIUM5.4openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php
CVE-2024-34019HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ...
CVE-2024-34018MEDIUM5.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap D...
CVE-2024-34017HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now