2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6717HIGH8.6HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to p...
CVE-2024-24507MEDIUM6.1Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser par...
CVE-2024-6913HIGH8.8Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windo...
CVE-2024-6912CRITICAL9.8Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all pron...
CVE-2024-6911HIGH7.5Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P...
CVE-2024-6806CRITICAL9.8The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These miss...
CVE-2024-6805CRITICAL9.8The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. Thes...
CVE-2024-6794CRITICAL9.8A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in r...
CVE-2024-6793CRITICAL9.8A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote c...
CVE-2024-6791HIGH7.8A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote co...
CVE-2024-40502CRITICAL9.8SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute ar...
CVE-2024-6675HIGH7.8A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Succ...
CVE-2024-6638MEDIUM5.5An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an i...
CVE-2024-6122MEDIUM5.5An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may r...
CVE-2024-6121HIGH7.8An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including ...
CVE-2024-39250CRITICAL9.8EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t...
CVE-2024-34329HIGH8.4Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch al...
CVE-2024-41880MEDIUM5.3In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effective...
CVE-2024-40075MEDIUM4.3Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.
CVE-2024-38944CRITICAL9.8An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the...
CVE-2024-37380MEDIUM5.3A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+...
CVE-2024-41130MEDIUM6.5llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_fr...
CVE-2024-40634HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability i...
CVE-2024-40051HIGH7.5IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.
CVE-2024-28698CRITICAL9.8Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now