2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9157HIGH7.8** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics...
CVE-2024-56338MEDIUM4.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-...
CVE-2024-55597HIGH7.2A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 thr...
CVE-2024-55592LOW3.8An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6....
CVE-2024-55590HIGH8.8Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
CVE-2024-54026HIGH8.8An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 t...
CVE-2024-54018HIGH7.2Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo...
CVE-2024-52961HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo...
CVE-2024-52960HIGH8.8A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 ...
CVE-2024-51322MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-51321HIGH7.6In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to...
CVE-2024-51320MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-51319HIGH7.3A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attac...
CVE-2024-46663MEDIUM6.7A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
CVE-2024-45328HIGH7.8An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged admin...
CVE-2024-45324HIGH7.2A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2...
CVE-2024-33501MEDIUM6.7Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti...
CVE-2024-32123MEDIUM6.7Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan...
CVE-2024-54085CRITICAL9.8AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish H...
CVE-2024-54084HIGH7APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition ...
CVE-2024-12546——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56336CRITICAL9.8A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0...
CVE-2024-56182HIGH8.2A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12...
CVE-2024-56181HIGH8.2A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07)...
CVE-2024-52285MEDIUM6.9A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now