2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-50567HIGH7.2An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0...
CVE-2024-40591HIGH7.2An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 ...
CVE-2024-40584HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-35279HIGH8.1A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 ...
CVE-2024-33504HIGH7.7A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7....
CVE-2024-47908HIGH7.2OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker ...
CVE-2024-13813HIGH7.1Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d...
CVE-2024-10644HIGH7.2Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows ...
CVE-2024-33659HIGH8.8AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker...
CVE-2024-54089HIGH8.7A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-54015HIGH8.7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All ve...
CVE-2024-53977HIGH7.8A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example se...
CVE-2024-53648HIGH7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All ve...
CVE-2024-45386HIGH8.8A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up...
CVE-2024-13643HIGH8.8The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi...
CVE-2024-57177HIGH7.3A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially ...
CVE-2024-8550HIGH7.5A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4...
CVE-2024-46436HIGH8.3Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the ...
CVE-2024-46435HIGH8A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote a...
CVE-2024-46434HIGH8.8Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized rem...
CVE-2024-46433HIGH8.8A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the...
CVE-2024-46432HIGH8.8Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POS...
CVE-2024-46431HIGH8Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can e...
CVE-2024-46429HIGH8.8A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access t...
CVE-2024-42512HIGH8.6Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now