2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-58388HIGH7.5Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability t...
CVE-2024-58387HIGH7.5Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint th...
CVE-2024-42002HIGH8.4A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool...
CVE-2024-14029HIGH7.5Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body a...
CVE-2024-58383HIGH7.3Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via ...
CVE-2024-58382HIGH7.5league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allo...
CVE-2024-58381HIGH7.5PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote...
CVE-2024-7956HIGH7.6A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit...
CVE-2024-35585HIGH8.6Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
CVE-2024-7953HIGH8.7A vulnerability exists in the affected products that allows a threat actor to create a project and become the administra...
CVE-2024-7952HIGH8.7A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to ...
CVE-2024-14047HIGH7.1A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by u...
CVE-2024-10085HIGH8.2CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of...
CVE-2024-13942HIGH7.6Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me...
CVE-2024-58375HIGH7.5OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into...
CVE-2024-58374HIGH7.5Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows r...
CVE-2024-39024HIGH8.8In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2024-6832HIGH7.5The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta...
CVE-2024-25039HIGH7.5IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2024-14040HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo...
CVE-2024-58330HIGH7.5A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret...
CVE-2024-58023HIGH8.4Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform...
CVE-2024-51316HIGH7.5The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g...
CVE-2024-58369HIGH7.1SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names...
CVE-2024-58368HIGH8.7SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now