2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8705MEDIUM6.3A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System ...
CVE-2024-7890HIGH7.3Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-7889HIGH7.3Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-8694MEDIUM5.1A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function u...
CVE-2024-8693MEDIUM5.1A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is s...
CVE-2024-8692CRITICAL9.8A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an ...
CVE-2024-44541CRITICAL9.8evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action...
CVE-2024-42760HIGH7.5SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /ap...
CVE-2024-8691HIGH7.1A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated Glob...
CVE-2024-8690MEDIUM4.4A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W...
CVE-2024-8689MEDIUM6A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of t...
CVE-2024-8688MEDIUM4.4An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CL...
CVE-2024-8687HIGH7.1An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user...
CVE-2024-8686HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass...
CVE-2024-8097MEDIUM6.7Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modul...
CVE-2024-44577HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
CVE-2024-44575LOW3.7RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could caus...
CVE-2024-44574HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
CVE-2024-44573MEDIUM4.7A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attac...
CVE-2024-44572HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
CVE-2024-44571HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
CVE-2024-44570HIGH8.8RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpi...
CVE-2024-20489MEDIUM5.5A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attac...
CVE-2024-20483HIGH7.2Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s...
CVE-2024-20406HIGH7.4A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now