2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52963MEDIUM5.9A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1...
CVE-2024-50566HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2024-50564LOW3.3A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versio...
CVE-2024-48893MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ...
CVE-2024-48890HIGH8.8An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-48886CRITICAL9.8A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0...
CVE-2024-48884CRITICAL9.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager ...
CVE-2024-47572HIGH8An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker t...
CVE-2024-47571CRITICAL9.8An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker ...
CVE-2024-47566MEDIUM6A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers...
CVE-2024-46670HIGH7.5An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below...
CVE-2024-46669MEDIUM6.5An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS...
CVE-2024-46668HIGH7.5An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4,...
CVE-2024-46667HIGH7.5A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all...
CVE-2024-46666MEDIUM5.3An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4....
CVE-2024-46665LOW3.7An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may a...
CVE-2024-46664MEDIUM4.9A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi...
CVE-2024-45326MEDIUM4.3An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all ...
CVE-2024-40587MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-36512HIGH7.2An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyze...
CVE-2024-36510MEDIUM5.3An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version...
CVE-2024-36506MEDIUM5.3An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr...
CVE-2024-36504MEDIUM6.5An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 ...
CVE-2024-35278MEDIUM4.3A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions ...
CVE-2024-35277HIGH7.5A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager versio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now