2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-36333HIGH7.8A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti...
CVE-2024-36323HIGH8.8Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf...
CVE-2024-21962HIGH8.6Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent...
CVE-2024-55045HIGH7.3Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry fun...
CVE-2024-47091HIGH7.8Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l...
CVE-2024-53326HIGH7.3LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(...
CVE-2024-46508HIGH7.5yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting ...
CVE-2024-46507HIGH7.3A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor...
CVE-2024-45257HIGH7.3A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi...
CVE-2024-33288HIGH7.3Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the ...
CVE-2024-27686HIGH7.5Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic...
CVE-2024-43384HIGH8A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor...
CVE-2024-30151HIGH8.3HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation...
CVE-2024-52911HIGH7.5Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is...
CVE-2024-13971HIGH7.5Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-...
CVE-2024-39847HIGH7.5Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. Thi...
CVE-2024-54013HIGH8.8Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server co...
CVE-2024-8010HIGH7.5The component accepts XML input through the publisher without disabling external entity resolution. This allows maliciou...
CVE-2024-53412HIGH8.4Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shel...
CVE-2024-33618HIGH7.5Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessiv...
CVE-2024-1490HIGH7.2An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management...
CVE-2024-14032HIGH7.8Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that ...
CVE-2024-14033HIGH8.7Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. A...
CVE-2024-44303HIGH7.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be ...
CVE-2024-44286HIGH7.5This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now