2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24991MEDIUM6.5A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth...
CVE-2024-23535HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-23534HIGH8.8An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticate...
CVE-2024-23533MEDIUM6.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23532HIGH7.5An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authentic...
CVE-2024-23531HIGH7.5An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthentica...
CVE-2024-23530HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23529HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23528HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23526HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-22061CRITICAL9.8A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenti...
CVE-2024-31750CRITICAL9.8SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the ...
CVE-2024-30938CRITICAL9.8SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID paramete...
CVE-2024-3742HIGH8.7Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the...
CVE-2024-22186HIGH8.8The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his priv...
CVE-2024-21872HIGH8.7The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages tha...
CVE-2024-21846MEDIUM6.9An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET requ...
CVE-2024-1491HIGH8.7The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentica...
CVE-2024-3741HIGH8.7Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attack...
CVE-2024-32473MEDIUM6.5Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distribut...
CVE-2024-30929HIGH8Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' ...
CVE-2024-30928HIGH8.1SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids'...
CVE-2024-30927MEDIUM6.3Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-r...
CVE-2024-30926MEDIUM4.6Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/k...
CVE-2024-30925MEDIUM6.5Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now