2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39835HIGH7.8A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af...
CVE-2024-39289HIGH7.8A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di...
CVE-2024-13972HIGH8.8A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024....
CVE-2024-32323HIGH8.1SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-12498——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-42912MEDIUM5.4A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac...
CVE-2024-9408CRITICAL9.8In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endp...
CVE-2024-9343MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-9342CRITICAL9.8In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation...
CVE-2024-10032MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-10031MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur...
CVE-2024-10029MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ...
CVE-2024-42650HIGH7.5NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability...
CVE-2024-42649MEDIUM6.5NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a ...
CVE-2024-42648MEDIUM6.5NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via ...
CVE-2024-42646HIGH7.5A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
CVE-2024-51770HIGH7.5An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51769HIGH7.5An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51768HIGH8An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-51767HIGH7.3An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2024-26293HIGH8.7The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the appli...
CVE-2024-26292HIGH7.1An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects ...
CVE-2024-26291HIGH8.7An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam...
CVE-2024-58258HIGH7.2SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can...
CVE-2024-41169HIGH7.5The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now