2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-42568CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport paramet...
CVE-2024-42567CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at ...
CVE-2024-42566CRITICAL9.8School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password paramete...
CVE-2024-42565CRITICAL9.8ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/co...
CVE-2024-42563CRITICAL9.8An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a c...
CVE-2024-42562CRITICAL9.8Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number ...
CVE-2024-42559CRITICAL9.8An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authent...
CVE-2024-42558CRITICAL9.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter...
CVE-2024-42556CRITICAL9.8Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type paramet...
CVE-2024-42336CRITICAL9.8Servision - CWE-287: Improper Authentication
CVE-2024-43202CRITICAL9.8Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2....
CVE-2024-6847CRITICAL9.8The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it...
CVE-2024-7777CRITICAL9The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-7947CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Point of Sales and Inventory Management System 1...
CVE-2024-7946CRITICAL9.8A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affect...
CVE-2024-5932CRITICAL9.8The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-7937CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerabili...
CVE-2024-7936CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affect...
CVE-2024-7935CRITICAL9.8A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected...
CVE-2024-7934CRITICAL9.8A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affec...
CVE-2024-7933CRITICAL9.8A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Aff...
CVE-2024-43354CRITICAL9.8Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through ...
CVE-2024-43328CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress a...
CVE-2024-43311CRITICAL9.8Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affec...
CVE-2024-42815CRITICAL9.8In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now