2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41973HIGH8.1A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file wri...
CVE-2024-41972MEDIUM6.5A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file r...
CVE-2024-41971HIGH8.1A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
CVE-2024-41970MEDIUM5.7A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for...
CVE-2024-48962HIGH8.8Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization ...
CVE-2024-47208CRITICAL9.8Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF...
CVE-2024-45791HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache...
CVE-2024-45505HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (i...
CVE-2024-41969HIGH8.8A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication...
CVE-2024-41968MEDIUM5.4A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
CVE-2024-41967HIGH8.1A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of ...
CVE-2024-41151HIGH8.8Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by author...
CVE-2024-49574HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
CVE-2024-22067HIGH8.8ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web modul...
CVE-2024-11315CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11314CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11313CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11312CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11311CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-5030LOW3.8The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, w...
CVE-2024-52947MEDIUM5.4A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary we...
CVE-2024-52946HIGH8.8An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated...
CVE-2024-52945HIGH7.8An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows...
CVE-2024-52944MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated rem...
CVE-2024-52943MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated rem...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now