2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21925HIGH8.2Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading ...
CVE-2024-21924HIGH8.2SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services h...
CVE-2024-0179HIGH8.2SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overw...
CVE-2024-21966HIGH7.3A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation,...
CVE-2024-12833MEDIUM6.1Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows n...
CVE-2024-12551HIGH7.8Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2024-12550HIGH7.8Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili...
CVE-2024-12549HIGH7.8Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2024-12548LOW3.3Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability a...
CVE-2024-12547HIGH8.8Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili...
CVE-2024-52968HIGH8.4An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to Ma...
CVE-2024-52966LOW2.3An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attac...
CVE-2024-50569HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 ...
CVE-2024-50567HIGH7.2An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0...
CVE-2024-40591HIGH7.2An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 ...
CVE-2024-40586MEDIUM6.7An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio...
CVE-2024-40584HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-36508MEDIUM6An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2024-35279HIGH8.1A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 ...
CVE-2024-33504HIGH7.7A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7....
CVE-2024-27781CRITICAL9An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2024-27780MEDIUM5.4Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i...
CVE-2024-12756MEDIUM6.1An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of ...
CVE-2024-12755MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential di...
CVE-2024-47908HIGH7.2OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now