2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5311CRITICAL9.8DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbit...
CVE-2024-35643MEDIUM5.9Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back B...
CVE-2024-35642MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaw...
CVE-2024-35641MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Ju...
CVE-2024-37031MEDIUM6.1The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations wher...
CVE-2024-36042CRITICAL9.8Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often prov...
CVE-2024-20075MEDIUM6.7In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2024-20074MEDIUM6.6In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2024-20073MEDIUM6.6In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca...
CVE-2024-20072MEDIUM6.6In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escal...
CVE-2024-20071MEDIUM4.4In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local inform...
CVE-2024-20070MEDIUM5.1In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establ...
CVE-2024-20069MEDIUM6.5In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade che...
CVE-2024-20068MEDIUM5.9In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2024-20067CRITICAL9.8In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial o...
CVE-2024-20066HIGH7.5In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of ...
CVE-2024-20065MEDIUM4In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf...
CVE-2024-5590CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This v...
CVE-2024-5589CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This...
CVE-2024-5588HIGH8.8A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by ...
CVE-2024-36392MEDIUM6.1MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-36391HIGH7.4MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
CVE-2024-36390HIGH7.5MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
CVE-2024-36389CRITICAL9.8MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
CVE-2024-36388CRITICAL9.8MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now