2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42560MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Managemen...
CVE-2024-42559CRITICAL9.8An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authent...
CVE-2024-42558CRITICAL9.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter...
CVE-2024-42557HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 all...
CVE-2024-42556CRITICAL9.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type paramet...
CVE-2024-42555HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 al...
CVE-2024-42554HIGH8.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type paramet...
CVE-2024-42553HIGH8.8A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allo...
CVE-2024-42552HIGH8.6Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter...
CVE-2024-42336CRITICAL9.8Servision - CWE-287: Improper Authentication
CVE-2024-42335MEDIUM5.47Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42334Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-41700HIGH7.5Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41699HIGH7.5Priority – CWE-552: Files or Directories Accessible to External Parties
CVE-2024-41698HIGH7.5Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41697MEDIUM6.1Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-25009MEDIUM6.5Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where im...
CVE-2024-7054MEDIUM5.4The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress...
CVE-2024-28829HIGH7.8Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p...
CVE-2024-21689HIGH8This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9....
CVE-2024-43202CRITICAL9.8Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2....
CVE-2024-38808MEDIUM4.3In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a speci...
CVE-2024-6847CRITICAL9.8The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it...
CVE-2024-5576MEDIUM5.4The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carouse...
CVE-2024-43688HIGH7.3cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now