2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6833MEDIUM5.9A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintex...
CVE-2024-29120MEDIUM5.9In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as...
CVE-2024-28993HIGH8.3The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. ...
CVE-2024-28992HIGH8.3The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. ...
CVE-2024-28074HIGH8.8It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While so...
CVE-2024-23475HIGH8.8The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. ...
CVE-2024-23474HIGH8.8The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosur...
CVE-2024-23472HIGH8SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an...
CVE-2024-23471HIGH8.8The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited,...
CVE-2024-23470HIGH8.8The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerabi...
CVE-2024-23469HIGH8.8SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulne...
CVE-2024-23468HIGH8.3The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. ...
CVE-2024-23467HIGH8.8The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. ...
CVE-2024-23466HIGH8.8SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If e...
CVE-2024-23465HIGH8.8The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnera...
CVE-2024-6765Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5471CRITICAL9.8Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the har...
CVE-2024-27311HIGH8.8Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which all...
CVE-2024-31411HIGH8.8Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an e...
CVE-2024-40617MEDIUM6.5Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated atta...
CVE-2024-36491CRITICAL9.8FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to ex...
CVE-2024-36475HIGH8.8FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulne...
CVE-2024-31979MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements....
CVE-2024-31070CRITICAL9.1Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series p...
CVE-2024-30471LOW3.7Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now