2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21324HIGH7.2Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2024-21323HIGH8.8Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2024-21322HIGH7.2Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2024-20693HIGH7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-20689HIGH7.1Secure Boot Security Feature Bypass Vulnerability
CVE-2024-20688HIGH7.1Secure Boot Security Feature Bypass Vulnerability
CVE-2024-20678HIGH8.8Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2024-20670HIGH8.1Outlook for Windows Spoofing Vulnerability
CVE-2024-3281HIGH8.8A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in...
CVE-2024-23671HIGH8.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2024-23662HIGH7.5An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 throug...
CVE-2024-21756HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2024-21755HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2024-3046HIGH7.5In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet ...
CVE-2024-31978HIGH7.6A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users t...
CVE-2024-31370HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKi...
CVE-2024-31367HIGH7.1Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
CVE-2024-30191HIGH8.4A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T...
CVE-2024-26275HIGH7.8A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa...
CVE-2024-31366HIGH7.1Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from ...
CVE-2024-31365HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type ...
CVE-2024-1233HIGH7.3A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP reques...
CVE-2024-2975HIGH7.5A race condition was identified through which privilege escalation was possible in certain configurations.
CVE-2024-27983HIGH8.2An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets...
CVE-2024-27901HIGH7.2SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now