2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6978HIGH8.8Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP...
CVE-2024-6977MEDIUM6.5A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, ...
CVE-2024-6975HIGH8.8Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Clien...
CVE-2024-6974HIGH7.8Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.3...
CVE-2024-6973HIGH8.8Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.
CVE-2024-41953MEDIUM6.1Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such ...
CVE-2024-41952MEDIUM5.3Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unkno...
CVE-2024-41950HIGH7.5Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vecto...
CVE-2024-41947MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a c...
CVE-2024-39694MEDIUM4.7Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to c...
CVE-2024-39318MEDIUM5.4The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload w...
CVE-2024-37901HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e...
CVE-2024-37900MEDIUM4.6XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading ...
CVE-2024-37898MEDIUM4.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has...
CVE-2024-7340HIGH8.8The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation...
CVE-2024-3083HIGH8.3A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations...
CVE-2024-3082MEDIUM4.6A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical acces...
CVE-2024-37135MEDIUM4.4DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potential...
CVE-2024-31203MEDIUM5.5A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer al...
CVE-2024-31202HIGH7.8A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a loca...
CVE-2024-31201MEDIUM6.7A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be...
CVE-2024-31200MEDIUM4.6A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker w...
CVE-2024-31199MEDIUM6.1A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users ...
CVE-2024-6208MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packag...
CVE-2024-39379MEDIUM5.5Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now