2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12728CRITICAL9.8A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than versi...
CVE-2024-12727CRITICAL9.8A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (...
CVE-2024-12672HIGH7.3A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the...
CVE-2024-12175HIGH7.8Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat...
CVE-2024-11364HIGH7.3Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow ...
CVE-2024-11157HIGH7.3A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the...
CVE-2024-7139MEDIUM6.5Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow tr...
CVE-2024-7138MEDIUM6.5An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed...
CVE-2024-7137MEDIUM6.5The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet ...
CVE-2024-53991MEDIUM5.9Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi...
CVE-2024-52794MEDIUM6.1Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affect...
CVE-2024-52589LOW2.7Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin ...
CVE-2024-49765CRITICAL9.1Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have loc...
CVE-2024-12111HIGH8In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Ac...
CVE-2024-56200HIGH8.6Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr...
CVE-2024-56159MEDIUM5.3Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read...
CVE-2024-55196HIGH7.5Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl...
CVE-2024-54150CRITICAL9.1cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type o...
CVE-2024-52897MEDIUM6.2IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive infor...
CVE-2024-51471MEDIUM5.3IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service...
CVE-2024-49336MEDIUM5.4IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated...
CVE-2024-38819HIGH7.5Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to pa...
CVE-2024-12794CRITICAL9.8A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown pa...
CVE-2024-12793MEDIUM4.3A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is ...
CVE-2024-12792CRITICAL9.8A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an u...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now