2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10013HIGH7.8In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through...
CVE-2024-10012HIGH7.8In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an i...
CVE-2024-50854HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.
CVE-2024-50853HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
CVE-2024-50852HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount ...
CVE-2024-49506HIGH7.3Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of se...
CVE-2024-49504HIGH7grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
CVE-2024-48989HIGH7.5A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke...
CVE-2024-47574HIGH7.8A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 ...
CVE-2024-4741HIGH7.5Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously fre...
CVE-2024-9409HIGH7.5CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive re...
CVE-2024-8937HIGH8.3CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a...
CVE-2024-8936HIGH8.3CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory a...
CVE-2024-8935HIGH7.7CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confide...
CVE-2024-10800HIGH8.8The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c...
CVE-2024-8933HIGH7.5CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-10816HIGH7.5The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6....
CVE-2024-10174HIGH7.3The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-39709HIGH7.8Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Se...
CVE-2024-38655HIGH7.2Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-38649HIGH7.5An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot...
CVE-2024-37400HIGH7.5An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg...
CVE-2024-37398HIGH7.8Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate t...
CVE-2024-37376HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34787HIGH7.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now