2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49369CRITICAL9.8Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat...
CVE-2024-30133MEDIUM5.3HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not suff...
CVE-2024-11006HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be...
CVE-2024-11005HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be...
CVE-2024-11004MEDIUM6.1Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a...
CVE-2024-10945HIGH7.3A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privi...
CVE-2024-10944HIGH8.4A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss...
CVE-2024-10943CRITICAL9.1An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets ac...
CVE-2024-10923HIGH8.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ A...
CVE-2024-9420HIGH8.8A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-8495HIGH7.5A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7...
CVE-2024-52297HIGH7.5Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon...
CVE-2024-52296MEDIUM6.5libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp...
CVE-2024-50331HIGH7.5An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak se...
CVE-2024-50330CRITICAL9.8SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50329HIGH8.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50328HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50327HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50326HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50324HIGH7.2Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50323HIGH7.8SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50322HIGH7.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50321HIGH7.5An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50320HIGH7.5An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50319HIGH7.5An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now