2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54269MEDIUM4.3Missing Authorization vulnerability in Ninja Team Notibar notibar allows Exploiting Incorrectly Configured Access Contro...
CVE-2024-12363HIGH7.1Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a...
CVE-2024-11737CRITICAL9.8CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidential...
CVE-2024-11401MEDIUM5.3Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, ...
CVE-2024-12283MEDIUM6.1The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions...
CVE-2024-12004MEDIUM6.1The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2024-10511MEDIUM6.3CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someon...
CVE-2024-53292MEDIUM6.7Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A l...
CVE-2024-53290HIGH8.4Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection')...
CVE-2024-53289HIGH7Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged at...
CVE-2024-52537MEDIUM6.7Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attac...
CVE-2024-11053LOW3.4When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used f...
CVE-2024-35117MEDIUM4.4IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the syste...
CVE-2024-55655LOW2.7sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer tha...
CVE-2024-55653MEDIUM6.5PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to c...
CVE-2024-54133LOW2.3Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) v...
CVE-2024-53960MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-53959HIGH7.8Adobe Framemaker versions 2020.7, 2022.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co...
CVE-2024-53958HIGH7.8Substance3D - Painter versions 10.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result...
CVE-2024-53957HIGH7.8Substance3D - Painter versions 10.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could ...
CVE-2024-53956HIGH7.8Premiere Pro versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res...
CVE-2024-53955HIGH7.8Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that co...
CVE-2024-53006MEDIUM5.5Substance3D - Modeler versions 1.14.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could re...
CVE-2024-53005MEDIUM5.5Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2024-53004MEDIUM5.5Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now