2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42915HIGH8A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token...
CVE-2024-42766MEDIUM5.4Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.
CVE-2024-42765CRITICAL9.8A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attacker...
CVE-2024-42764CRITICAL9.4Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.
CVE-2024-42040HIGH8.1Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today o...
CVE-2024-41150MEDIUM6.1An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDe...
CVE-2024-38869MEDIUM5.4Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configu...
CVE-2024-37311HIGH8.2Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, ...
CVE-2024-5586HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet loc...
CVE-2024-5556HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports modu...
CVE-2024-5490HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate re...
CVE-2024-5467HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lock...
CVE-2024-5466HIGH8.8Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the aut...
CVE-2024-36517HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts modul...
CVE-2024-36516HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N...
CVE-2024-36515HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N...
CVE-2024-36514HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary...
CVE-2024-43883HIGH7In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new re...
CVE-2024-7986HIGH7.5A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensiti...
CVE-2024-5502MEDIUM5.4The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag...
CVE-2024-38807MEDIUM6.3Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature v...
CVE-2024-43105MEDIUM4.3Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a...
CVE-2024-40766CRITICAL9.8An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially lea...
CVE-2024-6715MEDIUM6.1The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerabil...
CVE-2024-3282MEDIUM4.8The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now