2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5905MEDIUM4.4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low p...
CVE-2024-5558MEDIUM6.4CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privilege...
CVE-2024-5557MEDIUM4.5CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credent...
CVE-2024-37878MEDIUM6.1Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh...
CVE-2024-22855MEDIUM5.4A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to exec...
CVE-2024-5897MEDIUM6.1A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro...
CVE-2024-5759MEDIUM6.3An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker...
CVE-2024-1891MEDIUM5.4A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker co...
CVE-2024-37304MEDIUM6.1NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it...
CVE-2024-37297MEDIUM5.4WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allo...
CVE-2024-36691MEDIUM6.3Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbi...
CVE-2024-31217MEDIUM6.5Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is presen...
CVE-2024-2300MEDIUM6.2HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an ou...
CVE-2024-5891MEDIUM4.2A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth tok...
CVE-2024-23445MEDIUM6.5It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security...
CVE-2024-5313MEDIUM6.5CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product networ...
CVE-2024-5056MEDIUM6.5CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the d...
CVE-2024-5674MEDIUM6.5The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PH...
CVE-2024-3492MEDIUM5.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-1766MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all ...
CVE-2024-2092MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter ...
CVE-2024-5742MEDIUM6.7A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If...
CVE-2024-5468MEDIUM6.5The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due ...
CVE-2024-5266MEDIUM5.4The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm...
CVE-2024-3925MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now