2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53494HIGH7.5Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone...
CVE-2024-56179HIGH7.8In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim...
CVE-2024-50641HIGH8.1An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera...
CVE-2024-57152HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit...
CVE-2024-53495HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon...
CVE-2024-57491HIGH8.8Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to ac...
CVE-2024-49827HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitiv...
CVE-2024-12612HIGH7.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac...
CVE-2024-53946HIGH8.8The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface....
CVE-2024-53945HIGH8.8The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSe...
CVE-2024-7402HIGH7Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamp...
CVE-2024-5477HIGH7.3A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escala...
CVE-2024-26009HIGH8.1An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6....
CVE-2024-54678HIGH8.6A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2024-52504HIGH8.7A vulnerability has been identified in SIPROTEC 4 6MD61 (All versions), SIPROTEC 4 6MD63 (All versions), SIPROTEC 4 6MD6...
CVE-2024-41985HIGH7.3A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41979HIGH8A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-58256HIGH7.8EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-56339HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re...
CVE-2024-48916HIGH8.1Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an ...
CVE-2024-45955HIGH7.3Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
CVE-2024-51473HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-49828HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-42655HIGH8.8An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system ...
CVE-2024-42651HIGH7.5NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vuln...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now