2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-52504HIGH8.7A vulnerability has been identified in SIPROTEC 4 6MD61 (All versions), SIPROTEC 4 6MD63 (All versions), SIPROTEC 4 6MD6...
CVE-2024-41985HIGH7.3A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41979HIGH8A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-58256HIGH7.8EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-56339HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re...
CVE-2024-48916HIGH8.1Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an ...
CVE-2024-45955HIGH7.3Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
CVE-2024-51473HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-49828HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-42655HIGH8.8An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system ...
CVE-2024-42651HIGH7.5NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vuln...
CVE-2024-42645HIGH7.5An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading...
CVE-2024-42644HIGH7.5FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which ...
CVE-2024-49342HIGH7.5IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacke...
CVE-2024-58264HIGH7.5The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
CVE-2024-58261HIGH7.5The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: N...
CVE-2024-13507HIGH7.5The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2024-13976HIGH8.5A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During th...
CVE-2024-13975HIGH8.5A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, ...
CVE-2024-48729HIGH7.1An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote a...
CVE-2024-12310HIGH7A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen...
CVE-2024-53286HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record ...
CVE-2024-13974HIGH8.1A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead...
CVE-2024-13973HIGH7.2A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potenti...
CVE-2024-41921HIGH7.8A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now