2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55573HIGH7.2An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19...
CVE-2024-53379HIGH7.5Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/2...
CVE-2024-57556MEDIUM6.1Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary cod...
CVE-2024-57386MEDIUM6.1Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile...
CVE-2024-57329MEDIUM5.4HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize o...
CVE-2024-57328CRITICAL9.8A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises bec...
CVE-2024-57326MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1...
CVE-2024-55195HIGH7.5An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (...
CVE-2024-55194CRITICAL9.8OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
CVE-2024-55193CRITICAL9.8OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
CVE-2024-55192CRITICAL9.8OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inline...
CVE-2024-53923HIGH7.2An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x...
CVE-2024-53588HIGH7.8A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL fil...
CVE-2024-50665MEDIUM5.5gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.
CVE-2024-50664HIGH7.8gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.
CVE-2024-55930CRITICAL9.8Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil...
CVE-2024-55929MEDIUM5.3A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou...
CVE-2024-55928HIGH7.5Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows atta...
CVE-2024-55927HIGH7.5A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weakn...
CVE-2024-55926CRITICAL9.8A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr...
CVE-2024-45672MEDIUM6IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ...
CVE-2024-55925HIGH7.5In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se...
CVE-2024-52331HIGH7.7ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea...
CVE-2024-52330CRITICAL9.5ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify...
CVE-2024-52329HIGH7.4ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now