2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1900MEDIUM5.5Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier a...
CVE-2024-1898MEDIUM4.3Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privilege...
CVE-2024-1764HIGH7.6Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allow...
CVE-2024-2179MEDIUM4.8Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insuff...
CVE-2024-25858HIGH8.4In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an ...
CVE-2024-25616LOW3.7Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in t...
CVE-2024-25615MEDIUM5.3 An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol ...
CVE-2024-25614CRITICAL9.1There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerabil...
CVE-2024-25613HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-25612HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-25611HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-1356HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-2056CRITICAL9.8Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi...
CVE-2024-2055CRITICAL9.8The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the...
CVE-2024-23296HIGH7.8A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i...
CVE-2024-23256LOW3.3A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's lo...
CVE-2024-23243LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and ...
CVE-2024-23225HIGH7.8A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, i...
CVE-2024-22255HIGH7.1VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malic...
CVE-2024-22254HIGH8.2VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may ...
CVE-2024-22253MEDIUM6.7VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious acto...
CVE-2024-22252MEDIUM6.7VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious acto...
CVE-2024-27931MEDIUM6.5Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in...
CVE-2024-27929HIGH7.1ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's Initi...
CVE-2024-27565CRITICAL9.8A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now