2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4163HIGH8The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovere...
CVE-2024-31755HIGH7.6cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of func...
CVE-2024-33673HIGH7.8An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacki...
CVE-2024-33672HIGH7.1An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to...
CVE-2024-33671HIGH7.1An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded S...
CVE-2024-33666HIGH8.6An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounti...
CVE-2024-32868HIGH8.1ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SM...
CVE-2024-31609HIGH7.1Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and...
CVE-2024-32324HIGH7.8Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to exe...
CVE-2024-3625HIGH7.3A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. ...
CVE-2024-3624HIGH7.3A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This...
CVE-2024-3622HIGH8.8A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text for...
CVE-2024-32358HIGH7.5An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in...
CVE-2024-28241HIGH7.8The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DL...
CVE-2024-28240HIGH7.8The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI ...
CVE-2024-1657HIGH8.1A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation fro...
CVE-2024-1139HIGH7.7A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote att...
CVE-2024-4171HIGH8.8A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHan...
CVE-2024-4024HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starti...
CVE-2024-4170HIGH8.8A vulnerability was found in Tenda 4G300 1.01.42. It has been rated as critical. This issue affects the function sub_429...
CVE-2024-4169HIGH8.8A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the funct...
CVE-2024-33247HIGH8.8Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php.
CVE-2024-25026HIGH7.5IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vul...
CVE-2024-4168HIGH8.8A vulnerability was found in Tenda 4G300 1.01.42. It has been classified as critical. This affects the function sub_4260...
CVE-2024-4167HIGH8.8A vulnerability was found in Tenda 4G300 1.01.42 and classified as critical. Affected by this issue is the function sub_...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now