2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9499HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lea...
CVE-2024-9498HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to p...
CVE-2024-9497HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to...
CVE-2024-9496HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead ...
CVE-2024-9495HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead t...
CVE-2024-9494HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead ...
CVE-2024-9493HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  ToolStick installer can lead to privileg...
CVE-2024-9492HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to ...
CVE-2024-9491HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to pri...
CVE-2024-9490HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to p...
CVE-2024-41739HIGH8.8IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized action...
CVE-2024-13409HIGH8.8The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v...
CVE-2024-13408HIGH8.8The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v...
CVE-2024-55573HIGH7.2An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19...
CVE-2024-53379HIGH7.5Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/2...
CVE-2024-55195HIGH7.5An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (...
CVE-2024-53923HIGH7.2An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x...
CVE-2024-53588HIGH7.8A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL fil...
CVE-2024-50664HIGH7.8gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.
CVE-2024-55928HIGH7.5Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows atta...
CVE-2024-55927HIGH7.5A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weakn...
CVE-2024-55925HIGH7.5In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se...
CVE-2024-52331HIGH7.7ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea...
CVE-2024-52329HIGH7.4ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack...
CVE-2024-11147HIGH7.6ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An at...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now