2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24554HIGH8.2Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the A...
CVE-2024-4460Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-24553HIGH7.5Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords ...
CVE-2024-24552HIGH8.8A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an...
CVE-2024-24551HIGH8.8A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code throu...
CVE-2024-24550HIGH8.1A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arb...
CVE-2024-4900MEDIUM6.1The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contr...
CVE-2024-4899MEDIUM5The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high...
CVE-2024-6280CRITICAL9.8A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This a...
CVE-2024-6279HIGH8.8A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by...
CVE-2024-6278HIGH8.8A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affect...
CVE-2024-6277HIGH8.8A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Aff...
CVE-2024-4499MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax ...
CVE-2024-6276HIGH8.8A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1...
CVE-2024-6275HIGH8.8A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerabil...
CVE-2024-6274HIGH8.8A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affec...
CVE-2024-3121LOW3.3A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version...
CVE-2024-39337MEDIUM6.5Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.
CVE-2024-39334MEDIUM6.5MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a...
CVE-2024-6273MEDIUM6.1A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by ...
CVE-2024-39331CRITICAL9.8In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe...
CVE-2024-4841LOW3.3A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode...
CVE-2024-6269HIGH7.2A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function ...
CVE-2024-6268CRITICAL9.8A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1...
CVE-2024-6267MEDIUM4.8A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now