2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32211MEDIUM5.5An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive informa...
CVE-2024-32210MEDIUM5.3The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default ...
CVE-2024-30176MEDIUM5.3In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared w...
CVE-2024-29010HIGH7.1The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially...
CVE-2024-33518MEDIUM5.3An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ...
CVE-2024-33517HIGH7.5An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ...
CVE-2024-33516HIGH7.5An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provi...
CVE-2024-33515HIGH7.5Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco...
CVE-2024-33514HIGH7.5Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco...
CVE-2024-33513MEDIUM5.9Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco...
CVE-2024-28764HIGH7.8IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection....
CVE-2024-25015HIGH7.5IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending...
CVE-2024-23480CRITICAL9.8A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Clien...
CVE-2024-23457HIGH7.8The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninst...
CVE-2024-20378HIGH7.5A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote ...
CVE-2024-20376HIGH7.5A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote ...
CVE-2024-20357MEDIUM5.9A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiat...
CVE-2024-33820HIGH7.5Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overf...
CVE-2024-28893HIGH7.7Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configur...
CVE-2024-33512CRITICAL9.8There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to...
CVE-2024-33511CRITICAL9.8There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticate...
CVE-2024-26305CRITICAL9.8There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code...
CVE-2024-26304CRITICAL9.8There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r...
CVE-2024-24912MEDIUM6.7A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions ...
CVE-2024-4368HIGH8.8Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now