2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21809HIGH7.3Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow ...
CVE-2024-21788HIGH7.8Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentia...
CVE-2024-21777HIGH7.3Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an ...
CVE-2024-21772HIGH7.8Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to pote...
CVE-2024-4733HIGH7.5The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrus...
CVE-2024-3286HIGH7.5 A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trig...
CVE-2024-1417HIGH7.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoin...
CVE-2024-27260HIGH8.4IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invsc...
CVE-2024-4956HIGH7.5Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version ...
CVE-2024-3640HIGH7An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote c...
CVE-2024-34905HIGH7.5FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerabil...
CVE-2024-31142HIGH7.5Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intende...
CVE-2024-20389HIGH7.8A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated...
CVE-2024-20326HIGH7.8A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated...
CVE-2024-30314HIGH7.8Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an ...
CVE-2024-30292HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could res...
CVE-2024-30291HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could res...
CVE-2024-30290HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could res...
CVE-2024-30289HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co...
CVE-2024-30288HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that cou...
CVE-2024-4838HIGH7.5The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 ...
CVE-2024-35299HIGH7.5In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
CVE-2024-4352HIGH8.8The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data ...
CVE-2024-4351HIGH8.8The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data ...
CVE-2024-4222HIGH8.2The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now