2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-52281HIGH8.9A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to...
CVE-2024-42193HIGH8.1HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid...
CVE-2024-50960HIGH7.2A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351...
CVE-2024-36842HIGH7.3An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220...
CVE-2024-56406HIGH8.4A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, ...
CVE-2024-13861HIGH7.8A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3....
CVE-2024-52280HIGH7.7A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch ...
CVE-2024-11129HIGH7.5An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10...
CVE-2024-38865HIGH8.8Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0...
CVE-2024-13874HIGH7.1The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-55354HIGH8.8Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot...
CVE-2024-52981HIGH7.5An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested ...
CVE-2024-54024HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-50565HIGH7.5A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio...
CVE-2024-46671HIGH7.2An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, versi...
CVE-2024-26013HIGH7.5A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio...
CVE-2024-41793HIGH7.5A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41792HIGH7.5A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41790HIGH7.2A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41789HIGH7.2A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41788HIGH7.2A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-45557HIGH7.8Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
CVE-2024-45552HIGH8.2Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t...
CVE-2024-45549HIGH7.7Information disclosure while creating MQ channels.
CVE-2024-43067HIGH7.8Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now