2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54131HIGH7.3The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug ...
CVE-2024-51772HIGH8An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti...
CVE-2024-45757HIGH7.2An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-set...
CVE-2024-51771HIGH8.8A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe...
CVE-2024-51114HIGH8.8An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute ar...
CVE-2024-50948HIGH7.5mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust s...
CVE-2024-48080HIGH7.5An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i...
CVE-2024-12053HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object co...
CVE-2024-52547HIGH7.2An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerabilit...
CVE-2024-41777HIGH7.5IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic k...
CVE-2024-41775HIGH7.5IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker ...
CVE-2024-52805HIGH7.5Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf...
CVE-2024-37302HIGH7.5Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a...
CVE-2024-29404HIGH7.8An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary co...
CVE-2024-54000HIGH7.5Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-11391HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-42422HIGH7.5Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unaut...
CVE-2024-10074HIGH7.8in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through ...
CVE-2024-47476HIGH7.8Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vuln...
CVE-2024-45106HIGH8.1Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us...
CVE-2024-49420HIGH7.5Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attacke...
CVE-2024-49413HIGH7.8Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers t...
CVE-2024-49410HIGH7.8Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary c...
CVE-2024-45068HIGH7.1Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. ...
CVE-2024-9200HIGH7.2A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG400...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now