2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42782 | CRITICAL | 9.8 | 0.4% | Aug 21, 2024 | A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an... |
| CVE-2024-42781 | CRITICAL | 9.8 | 0.7% | Aug 21, 2024 | A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote ... |
| CVE-2024-42777 | CRITICAL | 9.8 | 0.7% | Aug 21, 2024 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management Sys... |
| CVE-2024-40453 | CRITICAL | 9.8 | 1.1% | Aug 21, 2024 | squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com... |
| CVE-2024-28000 | CRITICAL | 9.8 | 67.9% | Aug 21, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affect... |
| CVE-2024-5335 | CRITICAL | 9.8 | 0.9% | Aug 21, 2024 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc... |
| CVE-2024-7854 | CRITICAL | 9.8 | 4.3% | Aug 21, 2024 | The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins... |
| CVE-2024-8023 | CRITICAL | 9.8 | 0.6% | Aug 21, 2024 | A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function ... |
| CVE-2024-42361 | CRITICAL | 9.8 | 1.1% | Aug 20, 2024 | Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId... |
| CVE-2024-6800 | CRITICAL | 9.8 | 1.5% | Aug 20, 2024 | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication wi... |
| CVE-2024-42919 | CRITICAL | 9.8 | 1.0% | Aug 20, 2024 | eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport. |
| CVE-2024-27185 | CRITICAL | 9.1 | 0.4% | Aug 20, 2024 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. |
| CVE-2024-43404 | CRITICAL | 9.8 | 1.1% | Aug 20, 2024 | MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT version... |
| CVE-2024-35540 | CRITICAL | 9 | 2.7% | Aug 20, 2024 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or... |
| CVE-2024-30949 | CRITICAL | 9.8 | 0.8% | Aug 20, 2024 | An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday f... |
| CVE-2024-8005 | CRITICAL | 9.8 | 0.7% | Aug 20, 2024 | A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init... |
| CVE-2024-8003 | CRITICAL | 9.8 | 0.8% | Aug 20, 2024 | A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the fun... |
| CVE-2024-33872 | CRITICAL | 9.8 | 0.5% | Aug 20, 2024 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code executio... |
| CVE-2024-42575 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
| CVE-2024-42574 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
| CVE-2024-42573 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
| CVE-2024-42572 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
| CVE-2024-42571 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
| CVE-2024-42570 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
| CVE-2024-42569 | CRITICAL | 9.8 | 0.6% | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now