2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41195 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate ... |
| CVE-2024-40462 | HIGH | 7.8 | 0.2% | May 22, 2025 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE c... |
| CVE-2024-40461 | HIGH | 7.8 | 0.2% | May 22, 2025 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE com... |
| CVE-2024-40460 | HIGH | 7.8 | 0.2% | May 22, 2025 | An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE |
| CVE-2024-40459 | HIGH | 7.8 | 0.2% | May 22, 2025 | An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the applicat... |
| CVE-2024-40458 | HIGH | 7.8 | 0.2% | May 22, 2025 | An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati... |
| CVE-2024-13958 | MEDIUM | 4.8 | 0.2% | May 22, 2025 | Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a... |
| CVE-2024-13957 | HIGH | 7.6 | 0.2% | May 22, 2025 | SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis iss... |
| CVE-2024-13956 | HIGH | 8.8 | 0.4% | May 22, 2025 | SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affect... |
| CVE-2024-13955 | CRITICAL | 9.4 | 0.3% | May 22, 2025 | 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a... |
| CVE-2024-13954 | MEDIUM | 6.5 | 0.2% | May 22, 2025 | Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too... |
| CVE-2024-13953 | MEDIUM | 6.9 | 0.3% | May 22, 2025 | Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a... |
| CVE-2024-13952 | HIGH | 8.7 | 0.4% | May 22, 2025 | Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator... |
| CVE-2024-13951 | HIGH | 7.6 | 0.2% | May 22, 2025 | One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThi... |
| CVE-2024-13950 | MEDIUM | 6.9 | 0.3% | May 22, 2025 | Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre... |
| CVE-2024-13949 | MEDIUM | 6.9 | 0.3% | May 22, 2025 | Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat... |
| CVE-2024-13948 | HIGH | 7.3 | 0.1% | May 22, 2025 | Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat... |
| CVE-2024-13947 | HIGH | 7.1 | 0.3% | May 22, 2025 | Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become com... |
| CVE-2024-13946 | HIGH | 7.1 | 1.0% | May 22, 2025 | DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting... |
| CVE-2024-9639 | HIGH | 8 | 0.5% | May 22, 2025 | Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. Th... |
| CVE-2024-52874 | HIGH | 8.8 | 6.6% | May 22, 2025 | In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks. |
| CVE-2024-13931 | HIGH | 7.5 | 0.4% | May 22, 2025 | Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials be... |
| CVE-2024-13930 | MEDIUM | 5.9 | 0.3% | May 22, 2025 | An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if sessio... |
| CVE-2024-13929 | HIGH | 7.5 | 0.6% | May 22, 2025 | Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become comp... |
| CVE-2024-13928 | HIGH | 7.5 | 0.3% | May 22, 2025 | SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session adm... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now