2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38499HIGH8.8CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul...
CVE-2024-56017HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects...
CVE-2024-52949HIGH7.5iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th...
CVE-2024-37775HIGH7.5Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh...
CVE-2024-37774HIGH8A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv...
CVE-2024-55104HIGH7.2Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin...
CVE-2024-55103HIGH7.2Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile....
CVE-2024-12666HIGH8.8A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an un...
CVE-2024-8058HIGH7.6An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ director...
CVE-2024-6001HIGH8.1An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the abili...
CVE-2024-4762HIGH7.8An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a l...
CVE-2024-54376HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-54284HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP...
CVE-2024-54283HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP...
CVE-2024-54279HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki...
CVE-2024-54257HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Ref...
CVE-2024-54249HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Advanc...
CVE-2024-56015HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: ...
CVE-2024-56013HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authenticatio...
CVE-2024-55990HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tsjippy Mollie for...
CVE-2024-55989HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kyle M Brown WP Si...
CVE-2024-55987HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ritesh Sanap Advan...
CVE-2024-55986HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service ser...
CVE-2024-55979HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age...
CVE-2024-55974HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martí Batlles Mart...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now