2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40484MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Managem...
CVE-2024-40482CRITICAL9.8An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System...
CVE-2024-40481MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Mana...
CVE-2024-40480CRITICAL9.8A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam S...
CVE-2024-40479HIGH8.1A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers ...
CVE-2024-40478MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1...
CVE-2024-40477CRITICAL9.8A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 al...
CVE-2024-40476HIGH8A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. ...
CVE-2024-40475HIGH8.8SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_re...
CVE-2024-40474MEDIUM5.4A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Managem...
CVE-2024-40473MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental M...
CVE-2024-40472CRITICAL9.8Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."
CVE-2024-3279CRITICAL9.1An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the i...
CVE-2024-39815HIGH7.5Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays ...
CVE-2024-39791CRITICAL9.8Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeat...
CVE-2024-39338HIGH7.5axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative...
CVE-2024-38989CRITICAL9.8izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability al...
CVE-2024-38219CRITICAL9Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-38218HIGH7.8Microsoft Edge (HTML-based) Memory Corruption Vulnerability
CVE-2024-38200MEDIUM6.5Microsoft Office Spoofing Vulnerability
CVE-2024-37826HIGH7.5A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP...
CVE-2024-37283MEDIUM6.5An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the lo...
CVE-2024-37023CRITICAL9.9Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeater...
CVE-2024-36518MEDIUM5.4Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a...
CVE-2024-36462HIGH7.5Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now