2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-14044MEDIUM6.3A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc...
CVE-2024-14043MEDIUM6.3A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data...
CVE-2024-14042MEDIUM6.3A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr...
CVE-2024-6541MEDIUM6.8The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy...
CVE-2024-39024HIGH8.8In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2024-8995MEDIUM4.9Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a...
CVE-2024-6832HIGH7.5The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta...
CVE-2024-10302MEDIUM5.8The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo...
CVE-2024-40683MEDIUM6.3IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-25039HIGH7.5IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2024-14041HIGH8.2In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno...
CVE-2024-14040HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo...
CVE-2024-58355CRITICAL9.3Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking...
CVE-2024-58354CRITICAL9.9cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti...
CVE-2024-58353CRITICAL9.3Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac...
CVE-2024-58330HIGH7.5A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret...
CVE-2024-58023HIGH8.4Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform...
CVE-2024-5300MEDIUM5.6An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura...
CVE-2024-51316HIGH7.5The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g...
CVE-2024-51315CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/Se...
CVE-2024-51314CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/se...
CVE-2024-51312CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/Se...
CVE-2024-51313CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/Se...
CVE-2024-51311CRITICAL9.8The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/Se...
CVE-2024-58370MEDIUM6.5SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now