2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10945HIGH7.3A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privi...
CVE-2024-10944HIGH8.4A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss...
CVE-2024-10923HIGH8.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ A...
CVE-2024-9420HIGH8.8A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-8495HIGH7.5A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7...
CVE-2024-52297HIGH7.5Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon...
CVE-2024-50331HIGH7.5An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak se...
CVE-2024-50329HIGH8.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50328HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50327HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50326HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50324HIGH7.2Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50323HIGH7.8SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50322HIGH7.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50321HIGH7.5An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50320HIGH7.5An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50319HIGH7.5An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50318HIGH7.5A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial o...
CVE-2024-50317HIGH7.5A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial o...
CVE-2024-47907HIGH7.5A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated ...
CVE-2024-47906HIGH7.8Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy...
CVE-2024-11007HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be...
CVE-2024-51564HIGH7.5A guest can trigger an infinite loop in the hda audio driver.
CVE-2024-45289HIGH7.5The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname....
CVE-2024-42442HIGH8.8APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations wit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now