2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-22002HIGH7.8CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdi...
CVE-2024-38348HIGH8.8CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ...
CVE-2024-38347HIGH8.8CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ...
CVE-2024-37802HIGH8.8CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ...
CVE-2024-5275HIGH7.8A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which...
CVE-2024-6109HIGH8.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by...
CVE-2024-38506HIGH8.1In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for w...
CVE-2024-38505HIGH7.5In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
CVE-2024-37081HIGH7.8The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth...
CVE-2024-33620HIGH8.6Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability...
CVE-2024-6080HIGH7.8A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code...
CVE-2024-37896HIGH8.8Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerabi...
CVE-2024-37890HIGH7.5ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.max...
CVE-2024-37305HIGH8.2oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS...
CVE-2024-38449HIGH7.7A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versi...
CVE-2024-37840HIGH8.8SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Co...
CVE-2024-37795HIGH7.5A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB inp...
CVE-2024-37794HIGH7.5Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 i...
CVE-2024-36973HIGH7.8In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the e...
CVE-2024-36577HIGH8.3apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
CVE-2024-0397HIGH7.4A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext method...
CVE-2024-4032HIGH7.5The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as ...
CVE-2024-36581HIGH7.6A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-da...
CVE-2024-37848HIGH8.4SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code vi...
CVE-2024-37621HIGH7.2StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shipp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now