2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21797HIGH7.2A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. ...
CVE-2024-7344HIGH8.2Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded ...
CVE-2024-56497MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers...
CVE-2024-55593LOW2.7A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3...
CVE-2024-55591CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro...
CVE-2024-54021MEDIUM5.8An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fort...
CVE-2024-52969MEDIUM6.5An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS...
CVE-2024-52967MEDIUM4.8An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6...
CVE-2024-52963MEDIUM5.9A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1...
CVE-2024-50566HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2024-50564LOW3.3A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versio...
CVE-2024-48893MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ...
CVE-2024-48890HIGH8.8An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-48886CRITICAL9.8A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0...
CVE-2024-48884CRITICAL9.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager ...
CVE-2024-47572HIGH8An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker t...
CVE-2024-47571CRITICAL9.8An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker ...
CVE-2024-47566MEDIUM6A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers...
CVE-2024-46670HIGH7.5An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below...
CVE-2024-46669MEDIUM6.5An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS...
CVE-2024-46668HIGH7.5An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4,...
CVE-2024-46667HIGH7.5A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all...
CVE-2024-46666MEDIUM5.3An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4....
CVE-2024-46665LOW3.7An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may a...
CVE-2024-46664MEDIUM4.9A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now