2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-32842HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32840HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-28981HIGH8.5Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses da...
CVE-2024-7890HIGH7.3Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-7889HIGH7.3Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-42760HIGH7.5SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /ap...
CVE-2024-8691HIGH7.1A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated Glob...
CVE-2024-8687HIGH7.1An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user...
CVE-2024-8686HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass...
CVE-2024-44577HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
CVE-2024-44574HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
CVE-2024-44572HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
CVE-2024-44571HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
CVE-2024-44570HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpi...
CVE-2024-20483HIGH7.2Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s...
CVE-2024-20406HIGH7.4A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci...
CVE-2024-20398HIGH7.8A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write fi...
CVE-2024-20381HIGH8.8A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is use...
CVE-2024-20317HIGH7.4A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergen...
CVE-2024-20304HIGH7.5A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthen...
CVE-2024-5760HIGH7.8The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creatio...
CVE-2024-45026HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corru...
CVE-2024-45023HIGH7.1In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array wi...
CVE-2024-39378HIGH7.8Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in a...
CVE-2024-8306HIGH7.8CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now