2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32010HIGH7.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...
CVE-2024-32009HIGH7.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...
CVE-2024-32008HIGH7.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...
CVE-2024-57695HIGH7.7An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to exec...
CVE-2024-47118HIGH7.5IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI...
CVE-2024-12125HIGH7.5A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is p...
CVE-2024-25621HIGH7.8containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 ...
CVE-2024-56426HIGH7.5An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,...
CVE-2024-13998MEDIUM6.5Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ...
CVE-2024-13997HIGH7.2Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administra...
CVE-2024-51317MEDIUM6.5An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
CVE-2024-13992MEDIUM5.4Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing pag...
CVE-2024-58273HIGH7.8Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacke...
CVE-2024-58272——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2...
CVE-2024-14009HIGH7.2Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The...
CVE-2024-14008HIGH7.2Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizar...
CVE-2024-14006MEDIUM6.1Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-su...
CVE-2024-14005HIGH8.8Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient valida...
CVE-2024-14004HIGH8.8Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handli...
CVE-2024-14003CRITICAL9.8Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ...
CVE-2024-14002MEDIUM5.5Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An...
CVE-2024-14001MEDIUM5.4Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report com...
CVE-2024-14000MEDIUM5.4Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report com...
CVE-2024-13999CRITICAL9.8Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP...
CVE-2024-13996CRITICAL9.8Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now