2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43706HIGH8.8Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
CVE-2024-32119MEDIUM4.8An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an u...
CVE-2024-41797MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK53...
CVE-2024-40625MEDIUM4.9GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspace...
CVE-2024-38524HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa...
CVE-2024-34711HIGH8.2GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne...
CVE-2024-29198HIGH8.2GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss...
CVE-2024-13090HIGH7.3A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure...
CVE-2024-13089HIGH7.5An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut...
CVE-2024-55595——Rejected reason: Not used
CVE-2024-47081MEDIUM5.3Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to...
CVE-2024-46452MEDIUM6.1A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b a...
CVE-2024-55585CRITICAL9In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, re...
CVE-2024-9994MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-9993MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-56805MEDIUM5.4A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vu...
CVE-2024-50406MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability c...
CVE-2024-13088HIGH7.8An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t...
CVE-2024-13087MEDIUM6.7A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have ...
CVE-2024-58114MEDIUM4Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnera...
CVE-2024-46941MEDIUM4.8SystemUI has an incorrect component protection setting, which allows access to specific information.
CVE-2024-56343MEDIUM6.5IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a speci...
CVE-2024-56342MEDIUM5.3IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when ...
CVE-2024-22330CRITICAL9.8IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes i...
CVE-2024-13967CRITICAL9.4This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now