2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58272Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2...
CVE-2024-14009HIGH7.2Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The...
CVE-2024-14008HIGH7.2Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizar...
CVE-2024-14006MEDIUM6.1Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-su...
CVE-2024-14005HIGH8.8Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient valida...
CVE-2024-14004HIGH8.8Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handli...
CVE-2024-14003CRITICAL9.8Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ...
CVE-2024-14002MEDIUM5.5Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An...
CVE-2024-14001MEDIUM5.4Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report com...
CVE-2024-14000MEDIUM5.4Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report com...
CVE-2024-13999CRITICAL9.8Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP...
CVE-2024-13996CRITICAL9.8Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password...
CVE-2024-13995HIGH8.8Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform...
CVE-2024-13994CRITICAL9.8Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i...
CVE-2024-13993MEDIUM6.1Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe...
CVE-2024-14012HIGH7.3Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. W...
CVE-2024-58269MEDIUM4.3A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp...
CVE-2024-45162CRITICAL9.8A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass...
CVE-2024-45161MEDIUM4.6A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via...
CVE-2024-14011Rejected reason: This is a duplicate.
CVE-2024-58274HIGH8.3Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a comm...
CVE-2024-55568HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2024-31573MEDIUM4XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us...
CVE-2024-42192MEDIUM5.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access...
CVE-2024-56143HIGH8.2Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now