2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31841HIGH7.5An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthent...
CVE-2024-22640HIGH7.5TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page wi...
CVE-2024-3684HIGH7.2A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an ...
CVE-2024-3646HIGH7.2A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-3470HIGH7.2An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us...
CVE-2024-32166HIGH8.8Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing att...
CVE-2024-31744HIGH7.5In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnera...
CVE-2024-32683HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimat...
CVE-2024-29969HIGH7.5When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message ...
CVE-2024-29961HIGH8.2A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping comman...
CVE-2024-29960HIGH7.5 In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every tim...
CVE-2024-29959HIGH8.6A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the B...
CVE-2024-29957HIGH7.5When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is st...
CVE-2024-27984HIGH7.1A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-27977HIGH8.1A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-27976HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-27975HIGH8.8An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authent...
CVE-2024-25000HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-24999HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-24998HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-24997HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-24995HIGH7.5A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated ...
CVE-2024-24994HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-24993HIGH7.5A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated ...
CVE-2024-24992HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now