2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50306CRITICAL9.1Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traff...
CVE-2024-50305HIGH7.5Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S...
CVE-2024-47916HIGH7.5Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-47915HIGH7.5VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-47914MEDIUM4.5VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)
CVE-2024-45254HIGH7.5VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-45253HIGH7.5Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-38479HIGH7.5Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ...
CVE-2024-2552MEDIUM6A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass...
CVE-2024-2551HIGH7.5A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to st...
CVE-2024-2550HIGH7.5A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an u...
CVE-2024-7787MEDIUM5.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Compute...
CVE-2024-11206HIGH7.5Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user info...
CVE-2024-9186HIGH8.6The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugi...
CVE-2024-10146MEDIUM5.4The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it ba...
CVE-2024-5082HIGH7.1A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Rep...
CVE-2024-5083MEDIUM5.1A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus...
CVE-2024-40410MEDIUM4.8Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for ...
CVE-2024-40408HIGH7.3Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create P...
CVE-2024-40407HIGH7.5A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root pat...
CVE-2024-40405HIGH8.1Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a ...
CVE-2024-40404CRITICAL9.8Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp...
CVE-2024-51027MEDIUM6.5Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the prov...
CVE-2024-50956MEDIUM6.5A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN ...
CVE-2024-50955HIGH7.5An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now