2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52964MEDIUM6.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2024-48892MEDIUM4.9A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers...
CVE-2024-40588MEDIUM4.4Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiC...
CVE-2024-33607MEDIUM5.6Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user...
CVE-2024-38805MEDIUM6.3EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A succe...
CVE-2024-41986MEDIUM6.8A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41983MEDIUM4.3A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41982MEDIUM5.7A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41980MEDIUM5.7A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-58238MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Resolve TX timeout error in p...
CVE-2024-58257MEDIUM6.7EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-58255MEDIUM6.7EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-42048MEDIUM6.5OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all...
CVE-2024-55401MEDIUM6.5An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.
CVE-2024-52680MEDIUM6.1EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
CVE-2024-55402MEDIUM5.34C Strategies Exonaut before v22.4 was discovered to contain an access control issue.
CVE-2024-55399MEDIUM6.54C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).
CVE-2024-55398MEDIUM6.54C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
CVE-2024-52885MEDIUM5.4The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticat...
CVE-2024-52890MEDIUM6.1IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to n...
CVE-2024-45183MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPE...
CVE-2024-51775MEDIUM5.3Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server...
CVE-2024-52279MEDIUM5.3Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac...
CVE-2024-41177MEDIUM6.1Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo...
CVE-2024-34327MEDIUM6.5Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the passwor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now