2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31960HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference ...
CVE-2024-45393MEDIUM6.4Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke...
CVE-2024-45323LOW2.7An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may all...
CVE-2024-45044HIGH8.8Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is ...
CVE-2024-43800MEDIUM4.7serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() ma...
CVE-2024-43799MEDIUM4.7Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendS...
CVE-2024-43796MEDIUM4.7Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing ...
CVE-2024-42423HIGH7.1Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citr...
CVE-2024-36511LOW3.7An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF)...
CVE-2024-35282MEDIUM4.6A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all ver...
CVE-2024-33508HIGH7.3An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine...
CVE-2024-31490MEDIUM6.5An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4...
CVE-2024-31489HIGH8.1AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0...
CVE-2024-27257MEDIUM4.3IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source...
CVE-2024-25074MEDIUM5.9An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos...
CVE-2024-25073MEDIUM5.9An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos...
CVE-2024-23185HIGH7.5Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably size...
CVE-2024-23184MEDIUM5Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header l...
CVE-2024-21753MEDIUM6A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2...
CVE-2024-8654CRITICAL9.8MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are calle...
CVE-2024-8443LOW2.9A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card...
CVE-2024-44867HIGH7.5phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.
CVE-2024-37728HIGH7.5Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 al...
CVE-2024-8369MEDIUM5.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Priv...
CVE-2024-6282MEDIUM5.4The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now