2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37979HIGH7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30092HIGH7.5Windows Hyper-V Remote Code Execution Vulnerability
CVE-2024-25885HIGH7.5An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial...
CVE-2024-20659HIGH7.1Windows Hyper-V Security Feature Bypass Vulnerability
CVE-2024-9381HIGH7.2Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass...
CVE-2024-9380HIGH7.2An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen...
CVE-2024-9379HIGH7.2SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with ad...
CVE-2024-9167HIGH7.8Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local a...
CVE-2024-9124HIGH7.5A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with re...
CVE-2024-8626HIGH7.5Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious...
CVE-2024-7612HIGH7.8Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application...
CVE-2024-47011HIGH7.5Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive infor...
CVE-2024-47008HIGH7.5Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak se...
CVE-2024-47007HIGH7.5A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenti...
CVE-2024-8215HIGH8.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Plat...
CVE-2024-47949HIGH7.5In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
CVE-2024-47948HIGH7.5In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
CVE-2024-45230HIGH7.5An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrun...
CVE-2024-45880HIGH8A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the S...
CVE-2024-45330HIGH7.2A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5...
CVE-2024-9005HIGH7.3CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the ser...
CVE-2024-8422HIGH7.8CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of co...
CVE-2024-3506HIGH7.3A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to i...
CVE-2024-47562HIGH8.8A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not...
CVE-2024-47196HIGH7.3A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now