2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7096MEDIUM5.4A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service...
CVE-2024-12224HIGH8.8Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create...
CVE-2024-54952HIGH7.5MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers ...
CVE-2024-49350HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12....
CVE-2024-53423MEDIUM5.6An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafte...
CVE-2024-51392HIGH8.8An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the ...
CVE-2024-22654HIGH7.5tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
CVE-2024-22653MEDIUM4.8yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se...
CVE-2024-52588HIGH7.5Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks ...
CVE-2024-57338MEDIUM6.5An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x...
CVE-2024-57337MEDIUM6.5An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.10...
CVE-2024-57336MEDIUM6.5Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unautho...
CVE-2024-47057MEDIUM5.3SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. T...
CVE-2024-47055MEDIUM4.3SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vul...
CVE-2024-47056MEDIUM5.1SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be direct...
CVE-2024-51453HIGH7.5IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. A...
CVE-2024-38341HIGH7.5IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than...
CVE-2024-54020MEDIUM4.3A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allo...
CVE-2024-45094MEDIUM5.4IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerabilit...
CVE-2024-11185MEDIUM6.5On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly ...
CVE-2024-13966HIGH7.3ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged ...
CVE-2024-49197MEDIUM6.5An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1...
CVE-2024-49196HIGH7.5An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of...
CVE-2024-56193MEDIUM5.1There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local inform...
CVE-2024-47090MEDIUM6.1Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now