2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21324 | HIGH | 7.2 | 2.3% | Apr 9, 2024 | Microsoft Defender for IoT Elevation of Privilege Vulnerability |
| CVE-2024-21323 | HIGH | 8.8 | 3.2% | Apr 9, 2024 | Microsoft Defender for IoT Remote Code Execution Vulnerability |
| CVE-2024-21322 | HIGH | 7.2 | 3.1% | Apr 9, 2024 | Microsoft Defender for IoT Remote Code Execution Vulnerability |
| CVE-2024-20693 | HIGH | 7.8 | 0.8% | Apr 9, 2024 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2024-20689 | HIGH | 7.1 | 1.3% | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2024-20688 | HIGH | 7.1 | 1.3% | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2024-20678 | HIGH | 8.8 | 2.5% | Apr 9, 2024 | Remote Procedure Call Runtime Remote Code Execution Vulnerability |
| CVE-2024-20670 | HIGH | 8.1 | 2.3% | Apr 9, 2024 | Outlook for Windows Spoofing Vulnerability |
| CVE-2024-3281 | HIGH | 8.8 | 0.5% | Apr 9, 2024 | A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in... |
| CVE-2024-23671 | HIGH | 8.1 | 1.2% | Apr 9, 2024 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2024-23662 | HIGH | 7.5 | 0.7% | Apr 9, 2024 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 throug... |
| CVE-2024-21756 | HIGH | 8.8 | 2.2% | Apr 9, 2024 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2024-21755 | HIGH | 8.8 | 2.5% | Apr 9, 2024 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2024-3046 | HIGH | 7.5 | 0.6% | Apr 9, 2024 | In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet ... |
| CVE-2024-31978 | HIGH | 7.6 | 0.5% | Apr 9, 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users t... |
| CVE-2024-31370 | HIGH | 8.5 | 0.5% | Apr 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKi... |
| CVE-2024-31367 | HIGH | 7.1 | 0.4% | Apr 9, 2024 | Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. |
| CVE-2024-30191 | HIGH | 8.4 | 0.2% | Apr 9, 2024 | A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T... |
| CVE-2024-26275 | HIGH | 7.8 | 0.2% | Apr 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa... |
| CVE-2024-31366 | HIGH | 7.1 | 0.5% | Apr 9, 2024 | Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from ... |
| CVE-2024-31365 | HIGH | 7.1 | 0.4% | Apr 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type ... |
| CVE-2024-1233 | HIGH | 7.3 | 0.8% | Apr 9, 2024 | A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP reques... |
| CVE-2024-2975 | HIGH | 7.5 | 0.4% | Apr 9, 2024 | A race condition was identified through which privilege escalation was possible in certain configurations. |
| CVE-2024-27983 | HIGH | 8.2 | 87.2% | Apr 9, 2024 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets... |
| CVE-2024-27901 | HIGH | 7.2 | 0.7% | Apr 9, 2024 | SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now