2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46336 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php. |
| CVE-2024-46334 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword par... |
| CVE-2024-44652 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastna... |
| CVE-2024-44648 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. |
| CVE-2024-44647 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php. |
| CVE-2024-44644 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. |
| CVE-2024-44641 | MEDIUM | 6.5 | 0.2% | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. |
| CVE-2024-55016 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in lo... |
| CVE-2024-44640 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parame... |
| CVE-2024-44639 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short pa... |
| CVE-2024-44636 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin... |
| CVE-2024-44635 | MEDIUM | 6.1 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters ... |
| CVE-2024-44633 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-passwor... |
| CVE-2024-44632 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recov... |
| CVE-2024-44630 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These incl... |
| CVE-2024-42749 | MEDIUM | 6.1 | 0.2% | Nov 14, 2025 | Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted ... |
| CVE-2024-7021 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to... |
| CVE-2024-13983 | MEDIUM | 6.3 | 0.1% | Nov 14, 2025 | Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform... |
| CVE-2024-13178 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform ... |
| CVE-2024-11920 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform... |
| CVE-2024-11919 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to ... |
| CVE-2024-48829 | MEDIUM | 6.7 | 0.2% | Nov 12, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Inj... |
| CVE-2024-45301 | MEDIUM | 5.3 | 0.2% | Nov 12, 2025 | Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can c... |
| CVE-2024-32014 | MEDIUM | 4.7 | 0.1% | Nov 11, 2025 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i... |
| CVE-2024-13998 | MEDIUM | 6.5 | 1.0% | Nov 3, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now