2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38496MEDIUM5.1The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group...
CVE-2024-38495MEDIUM5.3A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
CVE-2024-6689HIGH7.8Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivil...
CVE-2024-38494HIGH8.6This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected P...
CVE-2024-38493MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convi...
CVE-2024-38492CRITICAL9.4This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ...
CVE-2024-38491HIGH8.4The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
CVE-2024-36458MEDIUM5.1The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.
CVE-2024-36457MEDIUM5.3The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
CVE-2024-36456CRITICAL9.4This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ...
CVE-2024-36455CRITICAL9.4An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM ...
CVE-2024-6721Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-5324. Reason: This record is a reservat...
CVE-2024-6746HIGH8.8A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerabi...
CVE-2024-5402HIGH7.8Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this...
CVE-2024-6745CRITICAL9.8A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown...
CVE-2024-6741MEDIUM5.3Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers c...
CVE-2024-6398MEDIUM5.3An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows inform...
CVE-2024-41007LOW3.3In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP so...
CVE-2024-39767MEDIUM6.5Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually cam...
CVE-2024-32945MEDIUM5.3Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows a...
CVE-2024-6740MEDIUM6.1Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject Jav...
CVE-2024-6540MEDIUM5.3Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS cou...
CVE-2024-23794HIGH7.5An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escala...
CVE-2024-6744CRITICAL9.8The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Ove...
CVE-2024-6743CRITICAL9.8AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now