2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-55597HIGH7.2A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 thr...
CVE-2024-55590HIGH8.8Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
CVE-2024-54026HIGH8.8An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 t...
CVE-2024-54018HIGH7.2Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo...
CVE-2024-52961HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo...
CVE-2024-52960HIGH8.8A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 ...
CVE-2024-51321HIGH7.6In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to...
CVE-2024-51319HIGH7.3A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attac...
CVE-2024-45328HIGH7.8An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged admin...
CVE-2024-45324HIGH7.2A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2...
CVE-2024-54084HIGH7APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition ...
CVE-2024-56182HIGH8.4A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12...
CVE-2024-56181HIGH8.4A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07)...
CVE-2024-13864HIGH7.1The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13862HIGH7.1The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise ...
CVE-2024-13836HIGH7.1The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13574HIGH7.1The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-12010HIGH7.2A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware v...
CVE-2024-12009HIGH7.2A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5....
CVE-2024-11253HIGH7.2A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyx...
CVE-2024-56192HIGH7.8In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This co...
CVE-2024-56191HIGH8.4In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to lo...
CVE-2024-54546HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to ca...
CVE-2024-44227HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An...
CVE-2024-11638HIGH8.8The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now