2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5065CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is a...
CVE-2024-34959MEDIUM5.5DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.
CVE-2024-5064CRITICAL9.8A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue...
CVE-2024-5063CRITICAL9.8A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vu...
CVE-2024-5022MEDIUM4.4The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This...
CVE-2024-34997HIGH7.5joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArra...
CVE-2024-3292HIGH8.2A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify...
CVE-2024-3291HIGH7.8When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions pri...
CVE-2024-3290HIGH8.2A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify insta...
CVE-2024-3289HIGH7.8When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3...
CVE-2024-35190MEDIUM5.3Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP...
CVE-2024-5072MEDIUM6.5Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authentic...
CVE-2024-4998Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-4566. Reason: This candidate is a r...
CVE-2024-34241MEDIUM4.8A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa...
CVE-2024-34058HIGH8.8The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).
CVE-2024-31974MEDIUM6.3The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote ...
CVE-2024-22429MEDIUM6.7Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privilege...
CVE-2024-5051HIGH8.8A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulne...
CVE-2024-35859MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: block: fix module reference leakage from bdev_open_...
CVE-2024-35858MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix memory leak when bringing down int...
CVE-2024-35857HIGH7.5In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possible NULL dereferences from icmp_...
CVE-2024-35856HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb ...
CVE-2024-35855HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-fr...
CVE-2024-35854HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-fr...
CVE-2024-35853MEDIUM6.4In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during re...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now