2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9465CRITICAL9.1An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition ...
CVE-2024-9464MEDIUM6.5An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary...
CVE-2024-9463HIGH7.5An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitra...
CVE-2024-46307HIGH7.5A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
CVE-2024-45746CRITICAL9.8An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a p...
CVE-2024-43610HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s...
CVE-2024-42988MEDIUM4.3Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows auth...
CVE-2024-46316HIGH8DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cg...
CVE-2024-46304HIGH7.5A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the...
CVE-2024-46292HIGH7.5A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserte...
CVE-2024-25825CRITICAL9.8FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be ...
CVE-2024-9675MEDIUM4.4A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are ...
CVE-2024-9671MEDIUM5.3A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is k...
CVE-2024-8048HIGH7.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object ...
CVE-2024-8015HIGH7.2In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible th...
CVE-2024-8014HIGH8.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through objec...
CVE-2024-7840HIGH7.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through im...
CVE-2024-7294MEDIUM6.5In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous...
CVE-2024-7293HIGH8.8In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible...
CVE-2024-7292HIGH8.8In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible th...
CVE-2024-47673MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is ...
CVE-2024-47672Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-47671MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbo...
CVE-2024-47670HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_xattr_find_entr...
CVE-2024-47669MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log w...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now