2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39575HIGH7.4update_disk_psu_baseline.sh requires password in plain text
CVE-2024-38487HIGH7api-gateway container running with root privilege would allow an attacker to escape the container and access host system...
CVE-2024-24909HIGH8.8Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the ga...
CVE-2024-22447HIGH7.8Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker...
CVE-2024-14036HIGH8.7Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-...
CVE-2024-52011HIGH8.3launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in...
CVE-2024-40646HIGH8.6Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co...
CVE-2024-56462HIGH8.8IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t...
CVE-2024-36334HIGH7Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta...
CVE-2024-36333HIGH7.8A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti...
CVE-2024-36323HIGH8.8Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf...
CVE-2024-21962HIGH8.6Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent...
CVE-2024-55045HIGH7.3Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry fun...
CVE-2024-47091HIGH7.8Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l...
CVE-2024-53326HIGH7.3LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(...
CVE-2024-46508HIGH7.5yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting ...
CVE-2024-46507HIGH7.3A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor...
CVE-2024-45257HIGH7.3A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi...
CVE-2024-33288HIGH7.3Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the ...
CVE-2024-27686HIGH7.5Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic...
CVE-2024-43384HIGH8A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor...
CVE-2024-30151HIGH8.3HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation...
CVE-2024-52911HIGH7.5Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is...
CVE-2024-13971HIGH7.5Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-...
CVE-2024-39847HIGH7.5Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. Thi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now