2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41195CRITICAL9.8An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate ...
CVE-2024-40462HIGH7.8An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE c...
CVE-2024-40461HIGH7.8An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE com...
CVE-2024-40460HIGH7.8An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
CVE-2024-40459HIGH7.8An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the applicat...
CVE-2024-40458HIGH7.8An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati...
CVE-2024-13958MEDIUM4.8Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a...
CVE-2024-13957HIGH7.6SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis iss...
CVE-2024-13956HIGH8.8SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affect...
CVE-2024-13955CRITICAL9.42nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a...
CVE-2024-13954MEDIUM6.5Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too...
CVE-2024-13953MEDIUM6.9Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a...
CVE-2024-13952HIGH8.7Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator...
CVE-2024-13951HIGH7.6One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThi...
CVE-2024-13950MEDIUM6.9Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre...
CVE-2024-13949MEDIUM6.9Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat...
CVE-2024-13948HIGH7.3Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat...
CVE-2024-13947HIGH7.1Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become com...
CVE-2024-13946HIGH7.1DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting...
CVE-2024-9639HIGH8Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. Th...
CVE-2024-52874HIGH8.8In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
CVE-2024-13931HIGH7.5Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials be...
CVE-2024-13930MEDIUM5.9An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if sessio...
CVE-2024-13929HIGH7.5Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become comp...
CVE-2024-13928HIGH7.5SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session adm...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now