2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22425 | CRITICAL | 9.8 | 0.5% | Feb 16, 2024 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthe... |
| CVE-2024-24377 | CRITICAL | 9.8 | 1.1% | Feb 16, 2024 | An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information ... |
| CVE-2024-25414 | CRITICAL | 9.8 | 1.6% | Feb 16, 2024 | An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code vi... |
| CVE-2024-0031 | CRITICAL | 9.8 | 0.6% | Feb 16, 2024 | In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input ... |
| CVE-2024-23674 | CRITICAL | 9.6 | 0.7% | Feb 15, 2024 | The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication byp... |
| CVE-2024-23479 | CRITICAL | 9.6 | 5.8% | Feb 15, 2024 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulner... |
| CVE-2024-23477 | CRITICAL | 9.6 | 7.8% | Feb 15, 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vu... |
| CVE-2024-23476 | CRITICAL | 9.6 | 7.1% | Feb 15, 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vu... |
| CVE-2024-25502 | CRITICAL | 9.8 | 1.4% | Feb 15, 2024 | Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sen... |
| CVE-2024-23113 | CRITICAL | 9.8 | 61.7% | Feb 15, 2024 | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.... |
| CVE-2024-20720 | CRITICAL | 9.1 | 3.7% | Feb 15, 2024 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special E... |
| CVE-2024-20719 | CRITICAL | 9.1 | 1.3% | Feb 15, 2024 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vul... |
| CVE-2024-20738 | CRITICAL | 9.8 | 1.1% | Feb 15, 2024 | Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability ... |
| CVE-2024-0390 | CRITICAL | 9.8 | 0.4% | Feb 15, 2024 | INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by ... |
| CVE-2024-26264 | CRITICAL | 9.8 | 0.8% | Feb 15, 2024 | EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page... |
| CVE-2024-26261 | CRITICAL | 9.8 | 0.7% | Feb 15, 2024 | The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulner... |
| CVE-2024-26260 | CRITICAL | 9.8 | 1.6% | Feb 15, 2024 | The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, all... |
| CVE-2024-24300 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardle... |
| CVE-2024-25223 | CRITICAL | 9.8 | 0.6% | Feb 14, 2024 | Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminV... |
| CVE-2024-25222 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManage... |
| CVE-2024-25220 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/E... |
| CVE-2024-25217 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /om... |
| CVE-2024-25216 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /apro... |
| CVE-2024-25215 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aproces... |
| CVE-2024-25214 | CRITICAL | 9.8 | 1.0% | Feb 14, 2024 | An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload int... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now