2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20659HIGH7.1Windows Hyper-V Security Feature Bypass Vulnerability
CVE-2024-9622MEDIUM5.3A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling...
CVE-2024-9621MEDIUM5.3A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the...
CVE-2024-9620MEDIUM5.3A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensit...
CVE-2024-9381HIGH7.2Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass...
CVE-2024-9380HIGH7.2An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen...
CVE-2024-9379HIGH7.2SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with ad...
CVE-2024-9167HIGH7.8Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local a...
CVE-2024-9124HIGH7.5A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with re...
CVE-2024-8626HIGH7.5Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious...
CVE-2024-7612HIGH7.8Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application...
CVE-2024-47011HIGH7.5Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive infor...
CVE-2024-47010CRITICAL9.8Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio...
CVE-2024-47009CRITICAL9.8Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio...
CVE-2024-47008HIGH7.5Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak se...
CVE-2024-47007HIGH7.5A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenti...
CVE-2024-45918CRITICAL9.8Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_g...
CVE-2024-44349CRITICAL9.8A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute ar...
CVE-2024-3057CRITICAL9.8A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.
CVE-2024-8215HIGH8.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Plat...
CVE-2024-47951MEDIUM5.4In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
CVE-2024-47950MEDIUM5.4In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
CVE-2024-47949HIGH7.5In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
CVE-2024-47948HIGH7.5In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
CVE-2024-47161MEDIUM6.5In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now