2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21818MEDIUM6.7Uncontrolled search path in some Intel(R) PCM software before version 202311 may allow an authenticated user to potentia...
CVE-2024-21814HIGH7.3Uncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authentic...
CVE-2024-21813HIGH7.9Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potenti...
CVE-2024-21809HIGH7.3Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow ...
CVE-2024-21792MEDIUM4.7Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authen...
CVE-2024-21788HIGH7.8Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentia...
CVE-2024-21777HIGH7.3Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an ...
CVE-2024-21774MEDIUM6.7Uncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 ...
CVE-2024-21772HIGH7.8Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to pote...
CVE-2024-4733HIGH7.5The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrus...
CVE-2024-31226LOW2.9Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a ser...
CVE-2024-5023CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe a...
CVE-2024-3286HIGH7.5 A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trig...
CVE-2024-1417HIGH7.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoin...
CVE-2024-27260HIGH8.4IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invsc...
CVE-2024-4956HIGH7.5Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version ...
CVE-2024-4609CRITICAL9.8A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor ...
CVE-2024-4603MEDIUM5.3Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use...
CVE-2024-3640HIGH7An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote c...
CVE-2024-35187CRITICAL9.1Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execut...
CVE-2024-35185MEDIUM5.3Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to ...
CVE-2024-35176MEDIUM5.3 REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XM...
CVE-2024-34808MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Opti...
CVE-2024-34805MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webvitaly i...
CVE-2024-34760MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now