2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22002 | HIGH | 7.8 | 0.4% | Jun 18, 2024 | CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdi... |
| CVE-2024-38348 | HIGH | 8.8 | 0.4% | Jun 18, 2024 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ... |
| CVE-2024-38347 | HIGH | 8.8 | 0.6% | Jun 18, 2024 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ... |
| CVE-2024-37802 | HIGH | 8.8 | 0.6% | Jun 18, 2024 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ... |
| CVE-2024-5275 | HIGH | 7.8 | 0.1% | Jun 18, 2024 | A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which... |
| CVE-2024-6109 | HIGH | 8.8 | 0.6% | Jun 18, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by... |
| CVE-2024-38506 | HIGH | 8.1 | 0.3% | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for w... |
| CVE-2024-38505 | HIGH | 7.5 | 0.4% | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site |
| CVE-2024-37081 | HIGH | 7.8 | 5.0% | Jun 18, 2024 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth... |
| CVE-2024-33620 | HIGH | 8.6 | 0.7% | Jun 18, 2024 | Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability... |
| CVE-2024-6080 | HIGH | 7.8 | 0.2% | Jun 17, 2024 | A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code... |
| CVE-2024-37896 | HIGH | 8.8 | 0.5% | Jun 17, 2024 | Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerabi... |
| CVE-2024-37890 | HIGH | 7.5 | 1.4% | Jun 17, 2024 | ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.max... |
| CVE-2024-37305 | HIGH | 8.2 | 0.4% | Jun 17, 2024 | oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS... |
| CVE-2024-38449 | HIGH | 7.7 | 1.0% | Jun 17, 2024 | A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versi... |
| CVE-2024-37840 | HIGH | 8.8 | 0.5% | Jun 17, 2024 | SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Co... |
| CVE-2024-37795 | HIGH | 7.5 | 0.5% | Jun 17, 2024 | A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB inp... |
| CVE-2024-37794 | HIGH | 7.5 | 0.5% | Jun 17, 2024 | Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 i... |
| CVE-2024-36973 | HIGH | 7.8 | 0.2% | Jun 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the e... |
| CVE-2024-36577 | HIGH | 8.3 | 0.4% | Jun 17, 2024 | apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty. |
| CVE-2024-0397 | HIGH | 7.4 | 0.8% | Jun 17, 2024 | A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext method... |
| CVE-2024-4032 | HIGH | 7.5 | 1.0% | Jun 17, 2024 | The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as ... |
| CVE-2024-36581 | HIGH | 7.6 | 0.5% | Jun 17, 2024 | A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-da... |
| CVE-2024-37848 | HIGH | 8.4 | 0.2% | Jun 17, 2024 | SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code vi... |
| CVE-2024-37621 | HIGH | 7.2 | 0.7% | Jun 17, 2024 | StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shipp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now