2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24915HIGH7.2Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ...
CVE-2024-52900MEDIUM5.4IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scrip...
CVE-2024-39730MEDIUM5.4IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim....
CVE-2024-36347MEDIUM6.4Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri...
CVE-2024-12364CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar...
CVE-2024-12150CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww...
CVE-2024-12143CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In...
CVE-2024-11739CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C...
CVE-2024-12827CRITICAL9.8The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take...
CVE-2024-52928HIGH8.3Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi...
CVE-2024-56915MEDIUM6.5Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.
CVE-2024-6174HIGH8.8When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven...
CVE-2024-11584MEDIUM5.3cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant...
CVE-2024-57708MEDIUM5.7An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __...
CVE-2024-27685HIGH7.1SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi...
CVE-2024-51984MEDIUM6.8An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ...
CVE-2024-51983HIGH7.5An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ...
CVE-2024-51982HIGH7.5An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr...
CVE-2024-51981MEDIUM5.3An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c...
CVE-2024-51980MEDIUM5.3An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ...
CVE-2024-51979HIGH7.2An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP...
CVE-2024-51978CRITICAL9.8An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password...
CVE-2024-51977MEDIUM5.3An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t...
CVE-2024-56917HIGH7.1Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.
CVE-2024-37743CRITICAL9.8An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now