2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-48957HIGH7.8execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c...
CVE-2024-39525HIGH8.7An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju...
CVE-2024-39516HIGH8.7An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS E...
CVE-2024-39515HIGH8.7An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Network...
CVE-2024-3656HIGH8.1A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access adminis...
CVE-2024-9473HIGH7.8A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticat...
CVE-2024-9468HIGH7.5A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-...
CVE-2024-9463HIGH7.5An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitra...
CVE-2024-46307HIGH7.5A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
CVE-2024-43610HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s...
CVE-2024-46316HIGH8DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cg...
CVE-2024-46304HIGH7.5A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the...
CVE-2024-46292HIGH7.5A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserte...
CVE-2024-8048HIGH7.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object ...
CVE-2024-8015HIGH7.2In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible th...
CVE-2024-8014HIGH8.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through objec...
CVE-2024-7840HIGH7.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through im...
CVE-2024-7293HIGH8.8In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible...
CVE-2024-7292HIGH8.8In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible th...
CVE-2024-47670HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_xattr_find_entr...
CVE-2024-47425HIGH7.8Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi...
CVE-2024-47424HIGH7.8Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability tha...
CVE-2024-47423HIGH7.8Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type ...
CVE-2024-47422HIGH7.8Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could l...
CVE-2024-47421HIGH7.8Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now