2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2743CRITICAL9.1An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3....
CVE-2024-6702MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
CVE-2024-6701MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
CVE-2024-6700MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
CVE-2024-6658MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This is...
CVE-2024-6510HIGH7.8Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileg...
CVE-2024-45826HIGH8.8CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists ...
CVE-2024-45825HIGH7.5CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a...
CVE-2024-45823CRITICAL9.8CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists...
CVE-2024-42484MEDIUM6.5ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discov...
CVE-2024-42483MEDIUM6.5ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered...
CVE-2024-45824CRITICAL9.8CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chai...
CVE-2024-40457CRITICAL9.1No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: t...
CVE-2024-28991HIGH8SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploite...
CVE-2024-28990HIGH8.8SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability....
CVE-2024-45857HIGH7.8Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously c...
CVE-2024-45856MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a J...
CVE-2024-45855HIGH7.5Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciou...
CVE-2024-45854HIGH7.5Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciou...
CVE-2024-45853HIGH7.5Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciou...
CVE-2024-45852HIGH8.8Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a malicious...
CVE-2024-45851HIGH8.8An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the ...
CVE-2024-45850HIGH8.8An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the ...
CVE-2024-45849HIGH8.8An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the ...
CVE-2024-45848HIGH8.8An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now