2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31841 | HIGH | 7.5 | 0.8% | Apr 19, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthent... |
| CVE-2024-22640 | HIGH | 7.5 | 1.3% | Apr 19, 2024 | TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page wi... |
| CVE-2024-3684 | HIGH | 7.2 | 1.1% | Apr 19, 2024 | A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an ... |
| CVE-2024-3646 | HIGH | 7.2 | 1.7% | Apr 19, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-3470 | HIGH | 7.2 | 0.6% | Apr 19, 2024 | An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us... |
| CVE-2024-32166 | HIGH | 8.8 | 0.7% | Apr 19, 2024 | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing att... |
| CVE-2024-31744 | HIGH | 7.5 | 0.7% | Apr 19, 2024 | In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnera... |
| CVE-2024-32683 | HIGH | 7.5 | 0.5% | Apr 19, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimat... |
| CVE-2024-29969 | HIGH | 7.5 | 0.3% | Apr 19, 2024 | When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message ... |
| CVE-2024-29961 | HIGH | 8.2 | 0.8% | Apr 19, 2024 | A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping comman... |
| CVE-2024-29960 | HIGH | 7.5 | 0.3% | Apr 19, 2024 | In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every tim... |
| CVE-2024-29959 | HIGH | 8.6 | 0.5% | Apr 19, 2024 | A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the B... |
| CVE-2024-29957 | HIGH | 7.5 | 0.3% | Apr 19, 2024 | When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is st... |
| CVE-2024-27984 | HIGH | 7.1 | 1.8% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-27977 | HIGH | 8.1 | 1.8% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-27976 | HIGH | 8.8 | 3.2% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-27975 | HIGH | 8.8 | 2.6% | Apr 19, 2024 | An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authent... |
| CVE-2024-25000 | HIGH | 8.8 | 3.0% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24999 | HIGH | 8.8 | 2.9% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24998 | HIGH | 8.8 | 3.2% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24997 | HIGH | 8.8 | 3.2% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24995 | HIGH | 7.5 | 2.4% | Apr 19, 2024 | A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated ... |
| CVE-2024-24994 | HIGH | 8.8 | 68.1% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24993 | HIGH | 7.5 | 2.4% | Apr 19, 2024 | A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated ... |
| CVE-2024-24992 | HIGH | 8.8 | 70.9% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now