2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13843MEDIUM4.4Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versio...
CVE-2024-13842MEDIUM4.4A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows...
CVE-2024-13830MEDIUM6.1Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a...
CVE-2024-13813HIGH7.1Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d...
CVE-2024-12797MEDIUM6.3Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server ...
CVE-2024-12058MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version...
CVE-2024-11771MEDIUM5.3Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted function...
CVE-2024-10644HIGH7.2Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows ...
CVE-2024-33659HIGH8.8AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker...
CVE-2024-12366CRITICAL9.8PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c...
CVE-2024-54090MEDIUM6A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-54089HIGH8.7A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-54015HIGH8.7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All ve...
CVE-2024-53977HIGH7.8A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example se...
CVE-2024-53651MEDIUM5.1A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),...
CVE-2024-53648HIGH7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All ve...
CVE-2024-45386HIGH8.8A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up...
CVE-2024-23814MEDIUM6.9The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory reso...
CVE-2024-13506MEDIUM6.4The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2024-52612MEDIUM4.8SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient ...
CVE-2024-52611LOW3.5The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the dat...
CVE-2024-52606CRITICAL9.8SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied al...
CVE-2024-45718MEDIUM4.6Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a l...
CVE-2024-28989MEDIUM5.5SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive in...
CVE-2024-13643HIGH8.8The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now