2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11772HIGH7.2Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker wit...
CVE-2024-11639CRITICAL9.8An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to...
CVE-2024-11634HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allo...
CVE-2024-11633HIGH7.2Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin pr...
CVE-2024-10256HIGH7.1Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbi...
CVE-2024-53866CRITICAL9.8The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one works...
CVE-2024-53247HIGH8.8In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure ...
CVE-2024-53246HIGH7.5In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2...
CVE-2024-53245MEDIUM4.3In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low...
CVE-2024-53244MEDIUM5.7In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2...
CVE-2024-53243MEDIUM4.3In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk ...
CVE-2024-12286CRITICAL9.8MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.
CVE-2024-55602HIGH8.5PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticate...
CVE-2024-55548HIGH7.5Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: throu...
CVE-2024-55547CRITICAL9.8SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.
CVE-2024-55546MEDIUM5.4Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects ...
CVE-2024-55545MEDIUM6.1Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420...
CVE-2024-46657MEDIUM5.5Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. Thi...
CVE-2024-45494CRITICAL9.8An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an ...
CVE-2024-45493CRITICAL9.8An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has int...
CVE-2024-55544HIGH8.8Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This iss...
CVE-2024-54152CRITICAL9.3Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3...
CVE-2024-10496HIGH7.8An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose informa...
CVE-2024-10495HIGH7.8An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disc...
CVE-2024-10494HIGH7.8An out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or r...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now