2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5311 | CRITICAL | 9.8 | 0.6% | Jun 3, 2024 | DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbit... |
| CVE-2024-35643 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back B... |
| CVE-2024-35642 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaw... |
| CVE-2024-35641 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Ju... |
| CVE-2024-37031 | MEDIUM | 6.1 | 0.3% | Jun 3, 2024 | The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations wher... |
| CVE-2024-36042 | CRITICAL | 9.8 | 0.9% | Jun 3, 2024 | Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often prov... |
| CVE-2024-20075 | MEDIUM | 6.7 | 0.1% | Jun 3, 2024 | In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of... |
| CVE-2024-20074 | MEDIUM | 6.6 | 0.2% | Jun 3, 2024 | In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2024-20073 | MEDIUM | 6.6 | 0.4% | Jun 3, 2024 | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca... |
| CVE-2024-20072 | MEDIUM | 6.6 | 0.4% | Jun 3, 2024 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escal... |
| CVE-2024-20071 | MEDIUM | 4.4 | 0.2% | Jun 3, 2024 | In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local inform... |
| CVE-2024-20070 | MEDIUM | 5.1 | 0.1% | Jun 3, 2024 | In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establ... |
| CVE-2024-20069 | MEDIUM | 6.5 | 0.6% | Jun 3, 2024 | In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade che... |
| CVE-2024-20068 | MEDIUM | 5.9 | 0.6% | Jun 3, 2024 | In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2024-20067 | CRITICAL | 9.8 | 0.7% | Jun 3, 2024 | In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial o... |
| CVE-2024-20066 | HIGH | 7.5 | 0.7% | Jun 3, 2024 | In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of ... |
| CVE-2024-20065 | MEDIUM | 4 | 0.1% | Jun 3, 2024 | In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf... |
| CVE-2024-5590 | CRITICAL | 9.8 | 0.6% | Jun 3, 2024 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This v... |
| CVE-2024-5589 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This... |
| CVE-2024-5588 | HIGH | 8.8 | 0.6% | Jun 2, 2024 | A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by ... |
| CVE-2024-36392 | MEDIUM | 6.1 | 0.3% | Jun 2, 2024 | MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-36391 | HIGH | 7.4 | 0.4% | Jun 2, 2024 | MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic |
| CVE-2024-36390 | HIGH | 7.5 | 0.4% | Jun 2, 2024 | MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service |
| CVE-2024-36389 | CRITICAL | 9.8 | 0.5% | Jun 2, 2024 | MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass |
| CVE-2024-36388 | CRITICAL | 9.8 | 0.5% | Jun 2, 2024 | MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now