2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13990CRITICAL9.3MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli...
CVE-2024-48851HIGH7.5Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an...
CVE-2024-25011MEDIUM5.3Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication chec...
CVE-2024-13151CRITICAL9.8CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In...
CVE-2024-48842HIGH7.3Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions
CVE-2024-13174HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web...
CVE-2024-13149CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ...
CVE-2024-12796MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT...
CVE-2024-12913HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communicat...
CVE-2024-12367HIGH8.6Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste...
CVE-2024-45434CRITICAL9.8OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo...
CVE-2024-45433MEDIUM6.5OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the B...
CVE-2024-45432HIGH7.5OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK B...
CVE-2024-45431MEDIUM5.3OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSD...
CVE-2024-47120MEDIUM6.8IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their...
CVE-2024-45671HIGH7.5IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algor...
CVE-2024-45669MEDIUM6.5IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of ...
CVE-2024-45325MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i...
CVE-2024-48341LOW3.7dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction....
CVE-2024-36354HIGH7.5Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r...
CVE-2024-36352HIGH8.4Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote...
CVE-2024-36346MEDIUM6Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen...
CVE-2024-36342HIGH8.8Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in ...
CVE-2024-36331LOW3.2Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN...
CVE-2024-36326HIGH8.4Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now