2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50318HIGH7.5A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial o...
CVE-2024-50317HIGH7.5A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial o...
CVE-2024-47909MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2...
CVE-2024-47907HIGH7.5A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated ...
CVE-2024-47906HIGH7.8Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy...
CVE-2024-47905MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2...
CVE-2024-47535MEDIUM5.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2024-43415CRITICAL9An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_aw...
CVE-2024-11007HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be...
CVE-2024-10971MEDIUM4.3Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious auth...
CVE-2024-8074CRITICAL9.3Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows...
CVE-2024-51566MEDIUM6.5The NVMe driver queue processing is vulernable to guest-induced infinite loops.
CVE-2024-51565MEDIUM6.5The hda driver is vulnerable to a buffer over-read from a guest-controlled value.
CVE-2024-51564HIGH7.5A guest can trigger an infinite loop in the hda audio driver.
CVE-2024-51563MEDIUM6.5The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2024-51562MEDIUM6.5The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.
CVE-2024-50386CRITICAL9.9Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary...
CVE-2024-45289HIGH7.5The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname....
CVE-2024-42442HIGH8.8APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations wit...
CVE-2024-39281MEDIUM5.3The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel...
CVE-2024-37365HIGH7.8A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects wi...
CVE-2024-33660MEDIUM5.2An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.
CVE-2024-33658HIGH7.8APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bou...
CVE-2024-2315HIGH7.1APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploita...
CVE-2024-11130MEDIUM4.8A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now