2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42451MEDIUM6.5A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th...
CVE-2024-42449HIGH7.1From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos...
CVE-2024-40717HIGH8.8A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code exe...
CVE-2024-11985MEDIUM4.4An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2...
CVE-2024-11479MEDIUM5.1A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user...
CVE-2024-46624HIGH8.8An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via ...
CVE-2024-53502LOW3.8Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
CVE-2024-51363CRITICAL9.8Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.
CVE-2024-46625HIGH8.8An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0....
CVE-2024-40391Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-54131HIGH7.3The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug ...
CVE-2024-53672MEDIUM6.3A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ...
CVE-2024-51773MEDIUM5.4A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe...
CVE-2024-51772HIGH8An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti...
CVE-2024-45757HIGH7.2An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-set...
CVE-2024-51771HIGH8.8A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe...
CVE-2024-51114HIGH8.8An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute ar...
CVE-2024-53921LOW2.8An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders ...
CVE-2024-50948HIGH7.5mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust s...
CVE-2024-48080HIGH7.5An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i...
CVE-2024-12053HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object co...
CVE-2024-52548MEDIUM6.7An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an...
CVE-2024-52547HIGH7.2An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerabilit...
CVE-2024-52546MEDIUM5.3An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerabil...
CVE-2024-52545MEDIUM6.5An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now