2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5905 | MEDIUM | 4.4 | 0.1% | Jun 12, 2024 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low p... |
| CVE-2024-5558 | MEDIUM | 6.4 | 0.1% | Jun 12, 2024 | CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privilege... |
| CVE-2024-5557 | MEDIUM | 4.5 | 0.2% | Jun 12, 2024 | CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credent... |
| CVE-2024-37878 | MEDIUM | 6.1 | 0.4% | Jun 12, 2024 | Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh... |
| CVE-2024-22855 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to exec... |
| CVE-2024-5897 | MEDIUM | 6.1 | 0.6% | Jun 12, 2024 | A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro... |
| CVE-2024-5759 | MEDIUM | 6.3 | 0.3% | Jun 12, 2024 | An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker... |
| CVE-2024-1891 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker co... |
| CVE-2024-37304 | MEDIUM | 6.1 | 0.7% | Jun 12, 2024 | NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it... |
| CVE-2024-37297 | MEDIUM | 5.4 | 0.5% | Jun 12, 2024 | WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allo... |
| CVE-2024-36691 | MEDIUM | 6.3 | 0.3% | Jun 12, 2024 | Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbi... |
| CVE-2024-31217 | MEDIUM | 6.5 | 0.7% | Jun 12, 2024 | Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is presen... |
| CVE-2024-2300 | MEDIUM | 6.2 | 0.2% | Jun 12, 2024 | HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an ou... |
| CVE-2024-5891 | MEDIUM | 4.2 | 0.2% | Jun 12, 2024 | A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth tok... |
| CVE-2024-23445 | MEDIUM | 6.5 | 0.5% | Jun 12, 2024 | It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security... |
| CVE-2024-5313 | MEDIUM | 6.5 | 0.4% | Jun 12, 2024 | CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product networ... |
| CVE-2024-5056 | MEDIUM | 6.5 | 0.3% | Jun 12, 2024 | CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the d... |
| CVE-2024-5674 | MEDIUM | 6.5 | 0.3% | Jun 12, 2024 | The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PH... |
| CVE-2024-3492 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-1766 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all ... |
| CVE-2024-2092 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter ... |
| CVE-2024-5742 | MEDIUM | 6.7 | 0.3% | Jun 12, 2024 | A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If... |
| CVE-2024-5468 | MEDIUM | 6.5 | 0.4% | Jun 12, 2024 | The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due ... |
| CVE-2024-5266 | MEDIUM | 5.4 | 0.4% | Jun 12, 2024 | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm... |
| CVE-2024-3925 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now