2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-3370HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software ...
CVE-2024-42392HIGH7.5Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite l...
CVE-2024-42386HIGH7.5Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42385HIGH7Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bou...
CVE-2024-42384HIGH7.5Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpect...
CVE-2024-41974HIGH7.1A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for cri...
CVE-2024-41973HIGH8.1A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file wri...
CVE-2024-41971HIGH8.1A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
CVE-2024-48962HIGH8.8Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization ...
CVE-2024-45791HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache...
CVE-2024-45505HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (i...
CVE-2024-41969HIGH8.8A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication...
CVE-2024-41967HIGH8.1A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of ...
CVE-2024-41151HIGH8.8Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by author...
CVE-2024-49574HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
CVE-2024-22067HIGH8.8ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web modul...
CVE-2024-52946HIGH8.8An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated...
CVE-2024-52945HIGH7.8An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows...
CVE-2024-11310HIGH7.5The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner...
CVE-2024-11309HIGH7.5The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner...
CVE-2024-52940HIGH7.5AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address wi...
CVE-2024-43704HIGH8.4Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics...
CVE-2024-52920HIGH7.5Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA ...
CVE-2024-52916HIGH7.5Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty h...
CVE-2024-52915HIGH7.5Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV m...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now