LiveActive security incident?Get immediate response
CVE archive

2024 CVE Archive

Browse CVE records published in 2024 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 38428 matching CVEs · Page 10 of 769.

High · CVSS 7.5

CVE-2024-55008: JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacke...

JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the attacker can trigger the account lockout mechanism on the account level, effectively locking the user out indefinitely. Since the lockout is applied to the user account and not based on the IP address, any attacker can trigger the lockout on any user account, regardless of their privileges.

Published Jan 7, 2025 · Updated Jul 5, 2026

High · CVSS 7.2

CVE-2024-48245: Vehicle Management System 1.0 is vulnerable to SQL Injection.

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php.

Published Jan 7, 2025 · Updated Jul 5, 2026