2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-30962HIGH7.8Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation...
CVE-2024-30961HIGH7.8Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig...
CVE-2024-53523HIGH7.5JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file functi...
CVE-2024-53589HIGH8.4GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex forma...
CVE-2024-11148HIGH8.7In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when ha...
CVE-2024-12235HIGH8.8A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a...
CVE-2024-12130HIGH7.8An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threa...
CVE-2024-11158HIGH8.5An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a...
CVE-2024-11156HIGH7.8An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a th...
CVE-2024-11155HIGH8.5A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat acto...
CVE-2024-53490HIGH7.5Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.
CVE-2024-53857HIGH7.5rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vul...
CVE-2024-53856HIGH7.5rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by provi...
CVE-2024-53472HIGH8.8WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2024-11941HIGH7.5A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, fr...
CVE-2024-53703HIGH8.1A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by...
CVE-2024-52271HIGH8.2User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Display...
CVE-2024-45318HIGH8.1A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buf...
CVE-2024-40763HIGH7.5Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote aut...
CVE-2024-6515HIGH8.1Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher p...
CVE-2024-54126HIGH8.5This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upg...
CVE-2024-51548HIGH8.8Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products: ABB ASPECT - Enterprise v...
CVE-2024-51546HIGH7.5Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPEC...
CVE-2024-51544HIGH8.2Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected produc...
CVE-2024-51543HIGH7.5Information Disclosure vulnerabilities allow access to application configuration information.  Affected products: ABB ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now