2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51551CRITICAL10Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default cred...
CVE-2024-51550CRITICAL9.8Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in ...
CVE-2024-51549CRITICAL9.4Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.  Affected products: ...
CVE-2024-51548HIGH8.8Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products: ABB ASPECT - Enterprise v...
CVE-2024-51546HIGH7.5Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPEC...
CVE-2024-51545CRITICAL9.8Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. ...
CVE-2024-51544HIGH8.2Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected produc...
CVE-2024-51543HIGH7.5Information Disclosure vulnerabilities allow access to application configuration information.  Affected products: ABB ...
CVE-2024-51542HIGH8.2Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products: ABB A...
CVE-2024-51541HIGH7.5Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - En...
CVE-2024-48847CRITICAL9.1MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or...
CVE-2024-48846HIGH7.3Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or chan...
CVE-2024-48845CRITICAL9.8Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that cou...
CVE-2024-48844MEDIUM6.5Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:...
CVE-2024-48843HIGH7.5Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:...
CVE-2024-48840CRITICAL9.8Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02;...
CVE-2024-48839CRITICAL9.8Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.0...
CVE-2024-12094MEDIUM5.4This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the devic...
CVE-2024-11317CRITICAL10Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportuni...
CVE-2024-11316HIGH7.5Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected produc...
CVE-2024-52270HIGH8.2User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Sp...
CVE-2024-52564HIGH7.5Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX f...
CVE-2024-47133HIGH7.2UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker...
CVE-2024-45841MEDIUM6.5Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/E...
CVE-2024-11779MEDIUM6.4The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocaro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now