2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-41148HIGH7.8A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff...
CVE-2024-39835HIGH7.8A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af...
CVE-2024-39289HIGH7.8A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di...
CVE-2024-13972HIGH8.8A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024....
CVE-2024-32323HIGH8.1SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-42650HIGH7.5NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability...
CVE-2024-42646HIGH7.5A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
CVE-2024-51770HIGH7.5An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51769HIGH7.5An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51768HIGH8An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51767HIGH7.3An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-26293HIGH8.7The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the appli...
CVE-2024-26292HIGH7.1An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects ...
CVE-2024-26291HIGH8.7An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam...
CVE-2024-58258HIGH7.2SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can...
CVE-2024-41169HIGH7.5The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in...
CVE-2024-47252HIGH7.5Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/...
CVE-2024-43394HIGH7.5Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a maliciou...
CVE-2024-43204HIGH7.5SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled ...
CVE-2024-42516HIGH7.5HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons...
CVE-2024-52965HIGH7.2A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0...
CVE-2024-53009HIGH7.8Memory corruption while operating the mailbox in Automotive.
CVE-2024-31854HIGH8.1A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect...
CVE-2024-31853HIGH8.1A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect...
CVE-2024-25177HIGH7.5LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now