2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-42782CRITICAL9.8A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an...
CVE-2024-42781CRITICAL9.8A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote ...
CVE-2024-42777CRITICAL9.8An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management Sys...
CVE-2024-40453CRITICAL9.8squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com...
CVE-2024-28000CRITICAL9.8Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affect...
CVE-2024-5335CRITICAL9.8The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc...
CVE-2024-7854CRITICAL9.8The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins...
CVE-2024-8023CRITICAL9.8A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function ...
CVE-2024-42361CRITICAL9.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId...
CVE-2024-6800CRITICAL9.8An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication wi...
CVE-2024-42919CRITICAL9.8eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
CVE-2024-27185CRITICAL9.1The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
CVE-2024-43404CRITICAL9.8MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT version...
CVE-2024-35540CRITICAL9A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or...
CVE-2024-30949CRITICAL9.8An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday f...
CVE-2024-8005CRITICAL9.8A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init...
CVE-2024-8003CRITICAL9.8A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the fun...
CVE-2024-33872CRITICAL9.8Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code executio...
CVE-2024-42575CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...
CVE-2024-42574CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...
CVE-2024-42573CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...
CVE-2024-42572CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...
CVE-2024-42571CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...
CVE-2024-42570CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...
CVE-2024-42569CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now