2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23535HIGH8.8A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ...
CVE-2024-23534HIGH8.8An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticate...
CVE-2024-23532HIGH7.5An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authentic...
CVE-2024-23531HIGH7.5An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthentica...
CVE-2024-23530HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23529HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23528HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-23526HIGH7.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-3742HIGH8.7Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the...
CVE-2024-22186HIGH8.8The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his priv...
CVE-2024-21872HIGH8.7The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages tha...
CVE-2024-1491HIGH8.7The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentica...
CVE-2024-3741HIGH8.7Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attack...
CVE-2024-30929HIGH8Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' ...
CVE-2024-30928HIGH8.1SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids'...
CVE-2024-22179HIGH8.7The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentia...
CVE-2024-30920HIGH7.4Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the...
CVE-2024-32477HIGH7.4Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a rac...
CVE-2024-20380HIGH7.5A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of servic...
CVE-2024-32462HIGH8.4Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before ...
CVE-2024-24910HIGH7.3A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for ...
CVE-2024-32475HIGH7.5Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enable...
CVE-2024-32602HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems Woo...
CVE-2024-32553HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Supe...
CVE-2024-32551HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now