2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47097MEDIUM5.1Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run...
CVE-2024-47096MEDIUM5.1Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run...
CVE-2024-56462HIGH8.8IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t...
CVE-2024-40684CRITICAL9.8IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-28765MEDIUM5.3IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote at...
CVE-2024-47272LOW2.7Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and...
CVE-2024-47271MEDIUM4.9Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-...
CVE-2024-47270LOW2.7Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo...
CVE-2024-47269MEDIUM4.9Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati...
CVE-2024-47268MEDIUM4.9Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2....
CVE-2024-47267LOW2.7Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functiona...
CVE-2024-11399MEDIUM6.8Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des...
CVE-2024-36343MEDIUM4.6Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to...
CVE-2024-36334HIGH7Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta...
CVE-2024-36333HIGH7.8A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti...
CVE-2024-36323HIGH8.8Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf...
CVE-2024-21950LOW1.8An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memo...
CVE-2024-36332MEDIUM6.8Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to...
CVE-2024-21962HIGH8.6Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent...
CVE-2024-36345MEDIUM4.6Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack...
CVE-2024-48519MEDIUM6.2Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attack...
CVE-2024-55045HIGH7.3Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry fun...
CVE-2024-51395MEDIUM6.2Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-51394MEDIUM5.5Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-47091HIGH7.8Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now