2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8711HIGH7.5A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1...
CVE-2024-8710HIGH8.8A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerabili...
CVE-2024-8709HIGH8.8A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affecte...
CVE-2024-37397HIGH8.2An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 Se...
CVE-2024-34785HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-34783HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-34779HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32848HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32846HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32845HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32843HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32842HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32840HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-28981HIGH8.5Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses da...
CVE-2024-7890HIGH7.3Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-7889HIGH7.3Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-42760HIGH7.5SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /ap...
CVE-2024-8691HIGH7.1A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated Glob...
CVE-2024-8687HIGH7.1An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user...
CVE-2024-8686HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass...
CVE-2024-44577HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
CVE-2024-44574HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
CVE-2024-44572HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
CVE-2024-44571HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
CVE-2024-44570HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now