2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50603CRITICAL9.8An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza...
CVE-2024-40679MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulner...
CVE-2024-10541——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. This is not ...
CVE-2024-55218MEDIUM6.1IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.
CVE-2024-54819CRITICAL9.1I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input valid...
CVE-2024-53522HIGH7.5Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe ...
CVE-2024-35532CRITICAL9.1An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attacke...
CVE-2024-40427HIGH7.9Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability...
CVE-2024-55414CRITICAL9.8A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged u...
CVE-2024-55413HIGH7.8A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users ...
CVE-2024-55412HIGH7.8A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to...
CVE-2024-55411HIGH8.8An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and ...
CVE-2024-55410——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-54007HIGH7.2Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead...
CVE-2024-54006HIGH7.2Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead...
CVE-2024-50660CRITICAL9.8File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload f...
CVE-2024-50659MEDIUM6.1Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privile...
CVE-2024-50658CRITICAL9.8Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code vi...
CVE-2024-44450MEDIUM5.4Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.
CVE-2024-8361HIGH7.5In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length tr...
CVE-2024-56272MEDIUM4.3Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-rol...
CVE-2024-56270MEDIUM5.3Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data...
CVE-2024-55555HIGH8.8Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_...
CVE-2024-40749HIGH7.5Improper Access Controls allows access to protected views.
CVE-2024-40748HIGH7.5Lack of output escaping in the id attribute of menu lists.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now