2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42649MEDIUM6.5NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a ...
CVE-2024-42648MEDIUM6.5NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via ...
CVE-2024-42646HIGH7.5A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
CVE-2024-51770HIGH7.5An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51769HIGH7.5An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51768HIGH8An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51767HIGH7.3An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-26293HIGH8.7The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the appli...
CVE-2024-26292HIGH7.1An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects ...
CVE-2024-26291HIGH8.7An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam...
CVE-2024-58258HIGH7.2SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can...
CVE-2024-41169HIGH7.5The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in...
CVE-2024-38648MEDIUM5.7A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensit...
CVE-2024-47065MEDIUM6.5Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not...
CVE-2024-47252HIGH7.5Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/...
CVE-2024-43394HIGH7.5Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a maliciou...
CVE-2024-43204HIGH7.5SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled ...
CVE-2024-42516HIGH7.5HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons...
CVE-2024-39752CRITICAL9.8IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type...
CVE-2024-38327CRITICAL9.8IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exp...
CVE-2024-37524MEDIUM5.3IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de...
CVE-2024-36697MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers...
CVE-2024-7650MEDIUM6.3Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Co...
CVE-2024-10391Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56468MEDIUM6.5IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now