2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5905MEDIUM4.4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low p...
CVE-2024-5898CRITICAL9.8A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this iss...
CVE-2024-5560HIGH7.5CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when a...
CVE-2024-5558MEDIUM6.4CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privilege...
CVE-2024-5557MEDIUM4.5CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credent...
CVE-2024-37878MEDIUM6.1Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh...
CVE-2024-37040HIGH8.1CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a ...
CVE-2024-37039HIGH7.5CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker s...
CVE-2024-37038HIGH8.8CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the de...
CVE-2024-37037HIGH8.1CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could a...
CVE-2024-37036CRITICAL9.8CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed...
CVE-2024-2230Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-22855MEDIUM5.4A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to exec...
CVE-2024-5897MEDIUM6.1A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro...
CVE-2024-5896CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging Sy...
CVE-2024-5759MEDIUM6.3An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker...
CVE-2024-37300HIGH8.1OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub <...
CVE-2024-36761CRITICAL9.8naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
CVE-2024-1891MEDIUM5.4A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker co...
CVE-2024-5895CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi...
CVE-2024-5894CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects u...
CVE-2024-5893CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unkno...
CVE-2024-37304MEDIUM6.1NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it...
CVE-2024-37297MEDIUM5.4WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allo...
CVE-2024-36840CRITICAL9.1SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now