2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-21949MEDIUM5.5Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, po...
CVE-2024-9999MEDIUM6.5In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Tr...
CVE-2024-9843MEDIUM5.5A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia...
CVE-2024-51750MEDIUM5Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f...
CVE-2024-50336MEDIUM5.3matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerabl...
CVE-2024-49527MEDIUM5.5Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl...
CVE-2024-30133MEDIUM5.3HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not suff...
CVE-2024-11004MEDIUM6.1Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a...
CVE-2024-52296MEDIUM6.5libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp...
CVE-2024-47909MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2...
CVE-2024-47905MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2...
CVE-2024-47535MEDIUM5.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2024-10971MEDIUM4.3Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious auth...
CVE-2024-51566MEDIUM6.5The NVMe driver queue processing is vulernable to guest-induced infinite loops.
CVE-2024-51565MEDIUM6.5The hda driver is vulnerable to a buffer over-read from a guest-controlled value.
CVE-2024-51563MEDIUM6.5The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2024-51562MEDIUM6.5The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.
CVE-2024-39281MEDIUM5.3The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel...
CVE-2024-33660MEDIUM5.2An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.
CVE-2024-11130MEDIUM4.8A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown ...
CVE-2024-11125MEDIUM4.3A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processi...
CVE-2024-50561MEDIUM6.1A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM...
CVE-2024-50560MEDIUM4.3A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM...
CVE-2024-50559MEDIUM4.3A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM...
CVE-2024-50558MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now