2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23907HIGH7.8Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authen...
CVE-2024-23499HIGH7.5Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E81...
CVE-2024-23497HIGH8.8Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before versi...
CVE-2024-23495HIGH7.8Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authen...
CVE-2024-23491HIGH7.3Uncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticat...
CVE-2024-23489HIGH7.3Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to po...
CVE-2024-22184HIGH7.8Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an...
CVE-2024-21801HIGH8.3Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privi...
CVE-2024-21787HIGH7.1Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentiall...
CVE-2024-21784HIGH7.8Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated u...
CVE-2024-39403HIGH7.6Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting...
CVE-2024-39402HIGH8.4Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of...
CVE-2024-39401HIGH8.4Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of...
CVE-2024-39400HIGH8.1Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Script...
CVE-2024-39399HIGH7.7Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a P...
CVE-2024-39398HIGH7.4Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Ex...
CVE-2024-4389HIGH8.8The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...
CVE-2024-41864HIGH7.8Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2024-41858HIGH7.8InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resu...
CVE-2024-7729HIGH7.5The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CG...
CVE-2024-7728HIGH7.2The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with admi...
CVE-2024-38653HIGH7.5XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t...
CVE-2024-37399HIGH7.5A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to c...
CVE-2024-37373HIGH7.2Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with...
CVE-2024-36136HIGH7.5An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now