2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6429 | MEDIUM | 4.3 | 0.2% | Sep 23, 2025 | A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain ... |
| CVE-2024-4598 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich me... |
| CVE-2024-25011 | MEDIUM | 5.3 | 0.3% | Sep 18, 2025 | Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication chec... |
| CVE-2024-12796 | MEDIUM | 5.3 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT... |
| CVE-2024-45433 | MEDIUM | 6.5 | 0.5% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the B... |
| CVE-2024-45431 | MEDIUM | 5.3 | 4.4% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSD... |
| CVE-2024-47120 | MEDIUM | 6.8 | 0.2% | Sep 10, 2025 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their... |
| CVE-2024-45669 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of ... |
| CVE-2024-45325 | MEDIUM | 6.7 | 0.5% | Sep 9, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i... |
| CVE-2024-36346 | MEDIUM | 6 | 0.1% | Sep 6, 2025 | Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen... |
| CVE-2024-21970 | MEDIUM | 4.4 | 0.1% | Sep 6, 2025 | Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt ... |
| CVE-2024-0028 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permissio... |
| CVE-2024-49731 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new ... |
| CVE-2024-40664 | MEDIUM | 6.2 | 0.1% | Sep 4, 2025 | In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s... |
| CVE-2024-49739 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to... |
| CVE-2024-43184 | MEDIUM | 6.1 | 0.2% | Sep 4, 2025 | IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnera... |
| CVE-2024-34598 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applicat... |
| CVE-2024-56189 | MEDIUM | 6.5 | 0.3% | Sep 4, 2025 | In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check... |
| CVE-2024-13073 | MEDIUM | 4.7 | 0.3% | Sep 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Ta... |
| CVE-2024-13071 | MEDIUM | 4.3 | 0.2% | Sep 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-... |
| CVE-2024-13066 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - ... |
| CVE-2024-13065 | MEDIUM | 6.3 | 0.2% | Sep 3, 2025 | Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows... |
| CVE-2024-13064 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft My... |
| CVE-2024-13063 | MEDIUM | 6.8 | 0.2% | Sep 3, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issu... |
| CVE-2024-49728 | MEDIUM | 5.5 | 0.1% | Sep 2, 2025 | In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now