2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53286HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record ...
CVE-2024-38335MEDIUM4.5IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of serv...
CVE-2024-55040MEDIUM6.1Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker ...
CVE-2024-13974HIGH8.1A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead...
CVE-2024-13973HIGH7.2A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potenti...
CVE-2024-6107CRITICAL9.8Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC c...
CVE-2024-13175MEDIUM5.5Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T...
CVE-2024-32124MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi...
CVE-2024-27779MEDIUM6.7An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version...
CVE-2024-42209LOW3.5HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive inf...
CVE-2024-41921HIGH7.8A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff...
CVE-2024-41148HIGH7.8A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff...
CVE-2024-39835HIGH7.8A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af...
CVE-2024-39289HIGH7.8A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di...
CVE-2024-13972HIGH8.8A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024....
CVE-2024-32323HIGH8.1SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-12498Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-42912MEDIUM5.4A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac...
CVE-2024-9408CRITICAL9.8In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endp...
CVE-2024-9343MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-9342CRITICAL9.8In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation...
CVE-2024-10032MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-10031MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur...
CVE-2024-10029MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ...
CVE-2024-42650HIGH7.5NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now