2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54009MEDIUM4Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be...
CVE-2024-12700HIGH8.8There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up...
CVE-2024-54984CRITICAL9.8An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this...
CVE-2024-54983CRITICAL9.8An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
CVE-2024-54982——An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS ...
CVE-2024-2201MEDIUM4.7A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fin...
CVE-2024-12729HIGH8.8A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho...
CVE-2024-12728CRITICAL9.8A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than versi...
CVE-2024-12727CRITICAL9.8A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (...
CVE-2024-12672HIGH7.3A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the...
CVE-2024-12175HIGH7.8Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat...
CVE-2024-11364HIGH7.3Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow ...
CVE-2024-11157HIGH7.3A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the...
CVE-2024-7139MEDIUM6.5Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow tr...
CVE-2024-7138MEDIUM6.5An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed...
CVE-2024-7137MEDIUM6.5The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet ...
CVE-2024-53991MEDIUM5.9Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi...
CVE-2024-52794MEDIUM6.1Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affect...
CVE-2024-52589LOW2.7Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin ...
CVE-2024-49765CRITICAL9.1Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have loc...
CVE-2024-12111HIGH8In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Ac...
CVE-2024-56200HIGH8.6Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr...
CVE-2024-56159MEDIUM5.3Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read...
CVE-2024-55196HIGH7.5Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl...
CVE-2024-54150CRITICAL9.1cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now