2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55017 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allow... |
| CVE-2024-57412 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP pa... |
| CVE-2024-43192 | HIGH | 8.8 | 0.2% | Sep 27, 2025 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attack... |
| CVE-2024-48014 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticat... |
| CVE-2024-48851 | HIGH | 7.5 | 0.5% | Sep 18, 2025 | Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an... |
| CVE-2024-48842 | HIGH | 7.3 | 0.2% | Sep 17, 2025 | Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions |
| CVE-2024-13174 | HIGH | 8.6 | 0.3% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web... |
| CVE-2024-12913 | HIGH | 8.8 | 0.2% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communicat... |
| CVE-2024-12367 | HIGH | 8.6 | 0.3% | Sep 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste... |
| CVE-2024-45432 | HIGH | 7.5 | 0.7% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK B... |
| CVE-2024-45671 | HIGH | 7.5 | 0.2% | Sep 10, 2025 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algor... |
| CVE-2024-36354 | HIGH | 7.5 | 0.2% | Sep 6, 2025 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r... |
| CVE-2024-36352 | HIGH | 8.4 | 0.1% | Sep 6, 2025 | Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote... |
| CVE-2024-36342 | HIGH | 8.8 | 0.2% | Sep 6, 2025 | Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in ... |
| CVE-2024-36326 | HIGH | 8.4 | 0.1% | Sep 6, 2025 | Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a... |
| CVE-2024-21947 | HIGH | 7.5 | 0.1% | Sep 6, 2025 | Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary m... |
| CVE-2024-49714 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea... |
| CVE-2024-56190 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T... |
| CVE-2024-13068 | HIGH | 7.3 | 0.1% | Sep 3, 2025 | Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: fro... |
| CVE-2024-43115 | HIGH | 8.8 | 0.5% | Sep 3, 2025 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s... |
| CVE-2024-49730 | HIGH | 7.8 | 0.1% | Sep 2, 2025 | In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation... |
| CVE-2024-49720 | HIGH | 7.8 | 0.1% | Sep 2, 2025 | In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi... |
| CVE-2024-40653 | HIGH | 7.3 | 0.1% | Sep 2, 2025 | In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba... |
| CVE-2024-58259 | HIGH | 8.2 | 0.5% | Sep 2, 2025 | A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert... |
| CVE-2024-52284 | HIGH | 7.7 | 0.2% | Sep 2, 2025 | Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now