2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42020MEDIUM5.4A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
CVE-2024-42019HIGH8A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This atta...
CVE-2024-40718HIGH8.8A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through e...
CVE-2024-40714HIGH8.3An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to...
CVE-2024-40713HIGH7.8A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alte...
CVE-2024-40712HIGH7.8A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perfor...
CVE-2024-40711CRITICAL9.8A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec...
CVE-2024-40710HIGH8.8A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service ...
CVE-2024-40709HIGH7.8A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to ...
CVE-2024-39718HIGH8.1An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with...
CVE-2024-39715HIGH8.5A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitra...
CVE-2024-39714CRITICAL9.9A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to re...
CVE-2024-38651HIGH8.5A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to...
CVE-2024-38650CRITICAL9.9An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on...
CVE-2024-8558MEDIUM4.3A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerab...
CVE-2024-36138HIGH8.1Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions ...
CVE-2024-36137LOW3.3A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs...
CVE-2024-8557HIGH7.5A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affect...
CVE-2024-8555MEDIUM6.1A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic...
CVE-2024-40681HIGH8.8IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define...
CVE-2024-8554MEDIUM5.4A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is...
CVE-2024-40680MEDIUM5.5IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation cau...
CVE-2024-37068HIGH7.5IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t...
CVE-2024-7620MEDIUM6.6The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2024-7112MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now