2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50567HIGH7.2An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0...
CVE-2024-40591HIGH7.2An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 ...
CVE-2024-40586MEDIUM6.7An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio...
CVE-2024-40584HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-36508MEDIUM6An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2024-35279HIGH8.1A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 ...
CVE-2024-33504HIGH7.7A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7....
CVE-2024-27781CRITICAL9An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2024-27780MEDIUM5.4Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i...
CVE-2024-12756MEDIUM6.1An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of ...
CVE-2024-12755MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential di...
CVE-2024-47908HIGH7.2OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker ...
CVE-2024-13843MEDIUM4.4Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versio...
CVE-2024-13842MEDIUM4.4A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows...
CVE-2024-13830MEDIUM6.1Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a...
CVE-2024-13813HIGH7.1Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d...
CVE-2024-12797MEDIUM6.3Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server ...
CVE-2024-12058MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version...
CVE-2024-11771MEDIUM5.3Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted function...
CVE-2024-10644HIGH7.2Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows ...
CVE-2024-33659HIGH8.8AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker...
CVE-2024-12366CRITICAL9.8PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c...
CVE-2024-54090MEDIUM6A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-54089HIGH8.7A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-54015HIGH8.7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All ve...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now