2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54678HIGH8.6A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2024-52504HIGH8.7A vulnerability has been identified in SIPROTEC 4 6MD61 (All versions), SIPROTEC 4 6MD63 (All versions), SIPROTEC 4 6MD6...
CVE-2024-41986MEDIUM6.8A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41985HIGH7.3A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41984LOW3.5A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41983MEDIUM4.3A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41982MEDIUM5.7A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41980MEDIUM5.7A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-41979HIGH8A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au...
CVE-2024-32640CRITICAL9.8MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, ...
CVE-2024-58238MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Resolve TX timeout error in p...
CVE-2024-58257MEDIUM6.7EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-58256HIGH7.8EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-58255MEDIUM6.7EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-42048MEDIUM6.5OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all...
CVE-2024-56339HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re...
CVE-2024-55401MEDIUM6.5An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.
CVE-2024-52680MEDIUM6.1EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
CVE-2024-55402MEDIUM5.34C Strategies Exonaut before v22.4 was discovered to contain an access control issue.
CVE-2024-55399MEDIUM6.54C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).
CVE-2024-55398MEDIUM6.54C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
CVE-2024-8244LOW3.7The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are ...
CVE-2024-52885MEDIUM5.4The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticat...
CVE-2024-52890MEDIUM6.1IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to n...
CVE-2024-45183MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPE...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now