2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5905 | MEDIUM | 4.4 | 0.1% | Jun 12, 2024 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low p... |
| CVE-2024-5898 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this iss... |
| CVE-2024-5560 | HIGH | 7.5 | 0.9% | Jun 12, 2024 | CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when a... |
| CVE-2024-5558 | MEDIUM | 6.4 | 0.1% | Jun 12, 2024 | CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privilege... |
| CVE-2024-5557 | MEDIUM | 4.5 | 0.2% | Jun 12, 2024 | CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credent... |
| CVE-2024-37878 | MEDIUM | 6.1 | 0.4% | Jun 12, 2024 | Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh... |
| CVE-2024-37040 | HIGH | 8.1 | 0.4% | Jun 12, 2024 | CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a ... |
| CVE-2024-37039 | HIGH | 7.5 | 0.8% | Jun 12, 2024 | CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker s... |
| CVE-2024-37038 | HIGH | 8.8 | 0.4% | Jun 12, 2024 | CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the de... |
| CVE-2024-37037 | HIGH | 8.1 | 1.0% | Jun 12, 2024 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could a... |
| CVE-2024-37036 | CRITICAL | 9.8 | 0.5% | Jun 12, 2024 | CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed... |
| CVE-2024-2230 | — | — | — | Jun 12, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-22855 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to exec... |
| CVE-2024-5897 | MEDIUM | 6.1 | 0.6% | Jun 12, 2024 | A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro... |
| CVE-2024-5896 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging Sy... |
| CVE-2024-5759 | MEDIUM | 6.3 | 0.3% | Jun 12, 2024 | An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker... |
| CVE-2024-37300 | HIGH | 8.1 | 0.4% | Jun 12, 2024 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub <... |
| CVE-2024-36761 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs. |
| CVE-2024-1891 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker co... |
| CVE-2024-5895 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi... |
| CVE-2024-5894 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects u... |
| CVE-2024-5893 | CRITICAL | 9.8 | 0.5% | Jun 12, 2024 | A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unkno... |
| CVE-2024-37304 | MEDIUM | 6.1 | 0.7% | Jun 12, 2024 | NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it... |
| CVE-2024-37297 | MEDIUM | 5.4 | 0.5% | Jun 12, 2024 | WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allo... |
| CVE-2024-36840 | CRITICAL | 9.1 | 2.2% | Jun 12, 2024 | SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now