2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-20741HIGH7.8Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could r...
CVE-2024-20740HIGH7.8Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2024-20723HIGH7.8Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in ar...
CVE-2024-24386HIGH7.2An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalp...
CVE-2024-0353HIGH7.8Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete file...
CVE-2024-1488HIGH7.3A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound grou...
CVE-2024-26263HIGH7.5EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse speci...
CVE-2024-26262HIGH8.8EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remot...
CVE-2024-1523HIGH8.8EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authent...
CVE-2024-24301HIGH8.8Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allo...
CVE-2024-1367HIGH7.2 A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the S...
CVE-2024-25618HIGH7.4Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configur...
CVE-2024-25617HIGH7.5Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into ...
CVE-2024-25165HIGH7.8A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.
CVE-2024-25301HIGH7.2Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates....
CVE-2024-0008HIGH8.8Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, maki...
CVE-2024-24990HIGH7.5When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p...
CVE-2024-24989HIGH7.5When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p...
CVE-2024-24775HIGH7.5When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traf...
CVE-2024-23982HIGH7.5 When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Tr...
CVE-2024-23979HIGH7.5 When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is co...
CVE-2024-23805HIGH7.5 Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility an...
CVE-2024-23314HIGH7.5When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management M...
CVE-2024-23308HIGH7.5 When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, un...
CVE-2024-23306HIGH7.1A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: S...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now