2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39024HIGH8.8In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2024-6832HIGH7.5The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta...
CVE-2024-25039HIGH7.5IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2024-14041HIGH8.2In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno...
CVE-2024-14040HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo...
CVE-2024-58330HIGH7.5A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret...
CVE-2024-58023HIGH8.4Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform...
CVE-2024-51316HIGH7.5The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g...
CVE-2024-58369HIGH7.1SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names...
CVE-2024-58368HIGH8.7SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s...
CVE-2024-58367HIGH7.1SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,...
CVE-2024-58365HIGH7.1SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls ...
CVE-2024-58362HIGH8.8SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operati...
CVE-2024-58361HIGH7.1SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code ...
CVE-2024-58359HIGH7.1SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r...
CVE-2024-58357HIGH7.1SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe...
CVE-2024-34268HIGH7.1EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow ...
CVE-2024-32386HIGH7.3Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at...
CVE-2024-7708HIGH7.5For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti...
CVE-2024-6228HIGH7.5The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value befo...
CVE-2024-58352HIGH8.7Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr...
CVE-2024-23581HIGH7.8The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized ...
CVE-2024-49269HIGH7.1Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
CVE-2024-32949HIGH8.3Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Con...
CVE-2024-32729HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversatio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now