2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13995HIGH8.8Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform...
CVE-2024-13994CRITICAL9.8Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i...
CVE-2024-13993MEDIUM6.1Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe...
CVE-2024-14012HIGH7.3Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. W...
CVE-2024-58269MEDIUM4.3A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp...
CVE-2024-45162CRITICAL9.8A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass...
CVE-2024-45161MEDIUM4.6A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via...
CVE-2024-14011——Rejected reason: This is a duplicate.
CVE-2024-58274HIGH8.3Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a comm...
CVE-2024-55568HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2024-31573MEDIUM4XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us...
CVE-2024-42192MEDIUM5.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access...
CVE-2024-56143HIGH8.2Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator...
CVE-2024-13991HIGH8.7Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supp...
CVE-2024-50571HIGH7.2A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7....
CVE-2024-48891HIGH7An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-47569MEDIUM4.3A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7...
CVE-2024-33507CRITICAL9.1An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For...
CVE-2024-26008MEDIUM5.3An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 a...
CVE-2024-44088MEDIUM6.1Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all...
CVE-2024-6211——Rejected reason: loading template...
CVE-2024-56804HIGH8.8An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, the...
CVE-2024-58267HIGH8A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is...
CVE-2024-58260HIGH7.6A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` fie...
CVE-2024-57494MEDIUM6.5Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now