2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13952HIGH8.7Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator...
CVE-2024-13951HIGH7.6One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThi...
CVE-2024-13950MEDIUM6.9Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre...
CVE-2024-13949MEDIUM6.9Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat...
CVE-2024-13948HIGH7.3Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat...
CVE-2024-13947HIGH7.1Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become com...
CVE-2024-13946HIGH7.1DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting...
CVE-2024-9639HIGH8Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. Th...
CVE-2024-52874HIGH8.8In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
CVE-2024-13931HIGH7.5Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials be...
CVE-2024-13930MEDIUM5.9An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if sessio...
CVE-2024-13929HIGH7.5Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become comp...
CVE-2024-13928HIGH7.5SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session adm...
CVE-2024-48853CRITICAL9.5An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a...
CVE-2024-48850HIGH7.5Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue aff...
CVE-2024-54188MEDIUM5.3Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root a...
CVE-2024-12093MEDIUM6.8An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2024-25010HIGH8.8Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp...
CVE-2024-9544MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
CVE-2024-57529MEDIUM6.1Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c...
CVE-2024-56428MEDIUM5.5The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the C...
CVE-2024-23337MEDIUM6.5jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning va...
CVE-2024-56429HIGH7.7itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users t...
CVE-2024-42922MEDIUM6.5AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
CVE-2024-12561MEDIUM6.1The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now