2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52963 | MEDIUM | 5.9 | 0.7% | Jan 14, 2025 | A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1... |
| CVE-2024-50566 | HIGH | 8.8 | 1.1% | Jan 14, 2025 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2024-50564 | LOW | 3.3 | 0.2% | Jan 14, 2025 | A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versio... |
| CVE-2024-48893 | MEDIUM | 5.4 | 0.4% | Jan 14, 2025 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ... |
| CVE-2024-48890 | HIGH | 8.8 | 1.1% | Jan 14, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-48886 | CRITICAL | 9.8 | 0.5% | Jan 14, 2025 | A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0... |
| CVE-2024-48884 | CRITICAL | 9.1 | 14.9% | Jan 14, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager ... |
| CVE-2024-47572 | HIGH | 8 | 0.6% | Jan 14, 2025 | An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker t... |
| CVE-2024-47571 | CRITICAL | 9.8 | 0.9% | Jan 14, 2025 | An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker ... |
| CVE-2024-47566 | MEDIUM | 6 | 0.2% | Jan 14, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers... |
| CVE-2024-46670 | HIGH | 7.5 | 0.6% | Jan 14, 2025 | An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below... |
| CVE-2024-46669 | MEDIUM | 6.5 | 0.6% | Jan 14, 2025 | An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS... |
| CVE-2024-46668 | HIGH | 7.5 | 1.0% | Jan 14, 2025 | An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4,... |
| CVE-2024-46667 | HIGH | 7.5 | 0.6% | Jan 14, 2025 | A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all... |
| CVE-2024-46666 | MEDIUM | 5.3 | 0.7% | Jan 14, 2025 | An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.... |
| CVE-2024-46665 | LOW | 3.7 | 0.5% | Jan 14, 2025 | An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may a... |
| CVE-2024-46664 | MEDIUM | 4.9 | 0.5% | Jan 14, 2025 | A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi... |
| CVE-2024-45326 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all ... |
| CVE-2024-40587 | MEDIUM | 6.7 | 0.6% | Jan 14, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-36512 | HIGH | 7.2 | 1.3% | Jan 14, 2025 | An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyze... |
| CVE-2024-36510 | MEDIUM | 5.3 | 0.7% | Jan 14, 2025 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version... |
| CVE-2024-36506 | MEDIUM | 5.3 | 0.5% | Jan 14, 2025 | An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr... |
| CVE-2024-36504 | MEDIUM | 6.5 | 0.7% | Jan 14, 2025 | An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 ... |
| CVE-2024-35278 | MEDIUM | 4.3 | 0.4% | Jan 14, 2025 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions ... |
| CVE-2024-35277 | HIGH | 7.5 | 0.7% | Jan 14, 2025 | A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager versio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now