2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36461HIGH8.8Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
CVE-2024-36460HIGH8.1The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te...
CVE-2024-36035HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session rec...
CVE-2024-36034HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate report...
CVE-2024-32765MEDIUM4.2A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local ...
CVE-2024-30188HIGH8.1File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional reso...
CVE-2024-29831HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox...
CVE-2024-29082HIGH8.6Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa...
CVE-2024-22123LOW2.7Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file fo...
CVE-2024-22122CRITICAL9.1Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat...
CVE-2024-22121MEDIUM6.1A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integri...
CVE-2024-22116HIGH7.2An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts ...
CVE-2024-22114MEDIUM4.3User with no permission to any of the Hosts can access and view host count & other statistics through System Information...
CVE-2024-21881HIGH8.6Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encryp...
CVE-2024-21880HIGH7.2Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter ...
CVE-2024-21879HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url paramet...
CVE-2024-21878CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway ...
CVE-2024-21877MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in ...
CVE-2024-21876CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enph...
CVE-2024-0115MEDIUM6.1NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may caus...
CVE-2024-0113HIGH8.8NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cau...
CVE-2024-42493MEDIUM5.3Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers an...
CVE-2024-42408LOW3.7The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which cou...
CVE-2024-41161CRITICAL9.8Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, so...
CVE-2024-39287HIGH7.5Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains pa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now