2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33382MEDIUM5.3An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVE-2024-25533CRITICAL9.4Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFil...
CVE-2024-25532CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/ge...
CVE-2024-25528MEDIUM5.9RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai...
CVE-2024-31961CRITICAL9.8A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbit...
CVE-2024-28971MEDIUM4.9Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log fi...
CVE-2024-25531CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit...
CVE-2024-25530CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit...
CVE-2024-25529CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_o...
CVE-2024-25527CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai...
CVE-2024-24908MEDIUM6.5Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A...
CVE-2024-24788MEDIUM5.9A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
CVE-2024-24787MEDIUM6.4On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ...
CVE-2024-22460HIGH7.2Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. A remote attacke...
CVE-2024-4654CRITICAL9.8A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This...
CVE-2024-4653HIGH7.5A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by t...
CVE-2024-3951HIGH7.1 PTC Codebeamer is vulnerable to a cross site scripting vulnerability that could allow an attacker to inject and execute...
CVE-2024-34347HIGH8.3@hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox p...
CVE-2024-33612MEDIUM6.8An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impe...
CVE-2024-33608HIGH7.5When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to ...
CVE-2024-33604MEDIUM6.1 A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that...
CVE-2024-32980CRITICAL9.1Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some...
CVE-2024-32761MEDIUM6.5Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running ...
CVE-2024-32113CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue ...
CVE-2024-32049HIGH7.4BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instanc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now