2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58348CRITICAL9.8WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate...
CVE-2024-27892CRITICAL9.6Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been...
CVE-2024-27891MEDIUM6.9On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies...
CVE-2024-27890CRITICAL9.6Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been...
CVE-2024-6858MEDIUM6.5In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there ...
CVE-2024-47273MEDIUM4.3An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functiona...
CVE-2024-47263MEDIUM4.1An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web...
CVE-2024-14036HIGH8.7Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-...
CVE-2024-42206LOW3.1HCL iReflection Third party vulnerable and outdated components issue was detected in the web application
CVE-2024-52011HIGH8.3launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in...
CVE-2024-40646HIGH8.6Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co...
CVE-2024-47097MEDIUM5.1Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run...
CVE-2024-47096MEDIUM5.1Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run...
CVE-2024-56462HIGH8.8IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t...
CVE-2024-40684CRITICAL9.8IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-28765MEDIUM5.3IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote at...
CVE-2024-47272LOW2.7Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and...
CVE-2024-47271MEDIUM4.9Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-...
CVE-2024-47270LOW2.7Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo...
CVE-2024-47269MEDIUM4.9Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati...
CVE-2024-47268MEDIUM4.9Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2....
CVE-2024-47267LOW2.7Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functiona...
CVE-2024-11399MEDIUM6.8Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des...
CVE-2024-36343MEDIUM4.6Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to...
CVE-2024-36334HIGH7Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now