2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6429MEDIUM4.3A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain ...
CVE-2024-4598MEDIUM6.5An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich me...
CVE-2024-25011MEDIUM5.3Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication chec...
CVE-2024-12796MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT...
CVE-2024-45433MEDIUM6.5OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the B...
CVE-2024-45431MEDIUM5.3OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSD...
CVE-2024-47120MEDIUM6.8IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their...
CVE-2024-45669MEDIUM6.5IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of ...
CVE-2024-45325MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i...
CVE-2024-36346MEDIUM6Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen...
CVE-2024-21970MEDIUM4.4Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt ...
CVE-2024-0028MEDIUM5.5In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permissio...
CVE-2024-49731MEDIUM4In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new ...
CVE-2024-40664MEDIUM6.2In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s...
CVE-2024-49739MEDIUM4In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to...
CVE-2024-43184MEDIUM6.1IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnera...
CVE-2024-34598MEDIUM5.5Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applicat...
CVE-2024-56189MEDIUM6.5In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check...
CVE-2024-13073MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Ta...
CVE-2024-13071MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-...
CVE-2024-13066MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - ...
CVE-2024-13065MEDIUM6.3Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows...
CVE-2024-13064MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft My...
CVE-2024-13063MEDIUM6.8Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issu...
CVE-2024-49728MEDIUM5.5In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now