2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-1618HIGH7.8A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.46...
CVE-2024-1226HIGH7.5The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing H...
CVE-2024-27907HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an...
CVE-2024-22044HIGH7.5A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affect...
CVE-2024-22041HIGH7.5A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x...
CVE-2024-22040HIGH7.5A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x...
CVE-2024-26288HIGH8.7An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a...
CVE-2024-26004HIGH7.5An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or...
CVE-2024-26003HIGH7.5An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt th...
CVE-2024-26002HIGH7.8An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by c...
CVE-2024-26000HIGH7.5An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The...
CVE-2024-25999HIGH7.8An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent ...
CVE-2024-25998HIGH7.3An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to im...
CVE-2024-27121HIGH7.2Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Seri...
CVE-2024-25325HIGH7.1SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information ...
CVE-2024-21805HIGH7.8Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior...
CVE-2024-28120HIGH7.5codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-ch...
CVE-2024-28198HIGH7.5OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manual...
CVE-2024-28197HIGH7.5Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its...
CVE-2024-28187HIGH7.2SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versi...
CVE-2024-27236HIGH8.4In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local es...
CVE-2024-27233HIGH7.8In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to ...
CVE-2024-27229HIGH7.5In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null...
CVE-2024-27226HIGH8.4In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to ...
CVE-2024-27224HIGH7.8In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now