2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-36460HIGH8.1The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te...
CVE-2024-36035HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session rec...
CVE-2024-36034HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate report...
CVE-2024-30188HIGH8.1File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional reso...
CVE-2024-29831HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox...
CVE-2024-29082HIGH8.6Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa...
CVE-2024-22116HIGH7.2An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts ...
CVE-2024-21881HIGH8.6Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encryp...
CVE-2024-21880HIGH7.2Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter ...
CVE-2024-21879HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url paramet...
CVE-2024-0113HIGH8.8NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cau...
CVE-2024-39287HIGH7.5Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains pa...
CVE-2024-37382HIGH7.2An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows att...
CVE-2024-0104HIGH8.8NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a us...
CVE-2024-42365HIGH8.8Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9...
CVE-2024-0108HIGH8.8NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean u...
CVE-2024-0107HIGH7.8NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use...
CVE-2024-0101HIGH7.5NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter ...
CVE-2024-42356HIGH7.2Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into a...
CVE-2024-41942HIGH7.2JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and ...
CVE-2024-7348HIGH7.5Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary...
CVE-2024-3659HIGH7.2Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen...
CVE-2024-3035HIGH8.1A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior t...
CVE-2024-2800HIGH7.5ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 pri...
CVE-2024-6329HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 pr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now