2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20670HIGH8.1Outlook for Windows Spoofing Vulnerability
CVE-2024-20669MEDIUM6.7Secure Boot Security Feature Bypass Vulnerability
CVE-2024-20665MEDIUM6.7BitLocker Security Feature Bypass Vulnerability
CVE-2024-3281HIGH8.8A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in...
CVE-2024-31868MEDIUM6.1Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and expo...
CVE-2024-31866CRITICAL9.8Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or ma...
CVE-2024-31865MEDIUM6.5Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im...
CVE-2024-31864CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sen...
CVE-2024-28235MEDIUM6.5Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, w...
CVE-2024-31487MEDIUM6.5A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2024-23671HIGH8.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2024-23662HIGH7.5An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 throug...
CVE-2024-21756HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2024-21755HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2024-28234MEDIUM4.7Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, i...
CVE-2024-28191MEDIUM5.4Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it...
CVE-2024-28190MEDIUM5.4Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, us...
CVE-2024-31544MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to exec...
CVE-2024-2224CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer compone...
CVE-2024-2223CRITICAL9.8An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Ser...
CVE-2024-31863MEDIUM5.3Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apa...
CVE-2024-3046HIGH7.5In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet ...
CVE-2024-31862MEDIUM5.3Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affect...
CVE-2024-31978HIGH7.6A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users t...
CVE-2024-31860MEDIUM6.5Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now