2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24991 | MEDIUM | 6.5 | 1.7% | Apr 19, 2024 | A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth... |
| CVE-2024-23535 | HIGH | 8.8 | 68.1% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-23534 | HIGH | 8.8 | 2.7% | Apr 19, 2024 | An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticate... |
| CVE-2024-23533 | MEDIUM | 6.5 | 1.4% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23532 | HIGH | 7.5 | 1.8% | Apr 19, 2024 | An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authentic... |
| CVE-2024-23531 | HIGH | 7.5 | 2.4% | Apr 19, 2024 | An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthentica... |
| CVE-2024-23530 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23529 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23528 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23526 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-22061 | CRITICAL | 9.8 | 3.6% | Apr 19, 2024 | A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenti... |
| CVE-2024-31750 | CRITICAL | 9.8 | 19.4% | Apr 19, 2024 | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the ... |
| CVE-2024-30938 | CRITICAL | 9.8 | 0.8% | Apr 19, 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID paramete... |
| CVE-2024-3742 | HIGH | 8.7 | 1.4% | Apr 18, 2024 | Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the... |
| CVE-2024-22186 | HIGH | 8.8 | 0.5% | Apr 18, 2024 | The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his priv... |
| CVE-2024-21872 | HIGH | 8.7 | 0.6% | Apr 18, 2024 | The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages tha... |
| CVE-2024-21846 | MEDIUM | 6.9 | 0.5% | Apr 18, 2024 | An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET requ... |
| CVE-2024-1491 | HIGH | 8.7 | 0.6% | Apr 18, 2024 | The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentica... |
| CVE-2024-3741 | HIGH | 8.7 | 0.5% | Apr 18, 2024 | Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attack... |
| CVE-2024-32473 | MEDIUM | 6.5 | 0.4% | Apr 18, 2024 | Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distribut... |
| CVE-2024-30929 | HIGH | 8 | 1.0% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' ... |
| CVE-2024-30928 | HIGH | 8.1 | 0.7% | Apr 18, 2024 | SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids'... |
| CVE-2024-30927 | MEDIUM | 6.3 | 0.6% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-r... |
| CVE-2024-30926 | MEDIUM | 4.6 | 0.5% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/k... |
| CVE-2024-30925 | MEDIUM | 6.5 | 0.6% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now