2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23535 | HIGH | 8.8 | 68.1% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-23534 | HIGH | 8.8 | 2.7% | Apr 19, 2024 | An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticate... |
| CVE-2024-23532 | HIGH | 7.5 | 1.8% | Apr 19, 2024 | An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authentic... |
| CVE-2024-23531 | HIGH | 7.5 | 2.4% | Apr 19, 2024 | An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthentica... |
| CVE-2024-23530 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23529 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23528 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-23526 | HIGH | 7.5 | 1.9% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-3742 | HIGH | 8.7 | 1.4% | Apr 18, 2024 | Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the... |
| CVE-2024-22186 | HIGH | 8.8 | 0.5% | Apr 18, 2024 | The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his priv... |
| CVE-2024-21872 | HIGH | 8.7 | 0.6% | Apr 18, 2024 | The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages tha... |
| CVE-2024-1491 | HIGH | 8.7 | 0.6% | Apr 18, 2024 | The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentica... |
| CVE-2024-3741 | HIGH | 8.7 | 0.5% | Apr 18, 2024 | Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attack... |
| CVE-2024-30929 | HIGH | 8 | 1.0% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' ... |
| CVE-2024-30928 | HIGH | 8.1 | 0.7% | Apr 18, 2024 | SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids'... |
| CVE-2024-22179 | HIGH | 8.7 | 0.4% | Apr 18, 2024 | The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentia... |
| CVE-2024-30920 | HIGH | 7.4 | 1.0% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-32477 | HIGH | 7.4 | 0.3% | Apr 18, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a rac... |
| CVE-2024-20380 | HIGH | 7.5 | 1.1% | Apr 18, 2024 | A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of servic... |
| CVE-2024-32462 | HIGH | 8.4 | 0.5% | Apr 18, 2024 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before ... |
| CVE-2024-24910 | HIGH | 7.3 | 0.2% | Apr 18, 2024 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for ... |
| CVE-2024-32475 | HIGH | 7.5 | 0.7% | Apr 18, 2024 | Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enable... |
| CVE-2024-32602 | HIGH | 7.2 | 0.5% | Apr 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems Woo... |
| CVE-2024-32553 | HIGH | 7.1 | 0.5% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Supe... |
| CVE-2024-32551 | HIGH | 7.6 | 0.5% | Apr 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now