2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57974MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: udp: Deal with race between UDP socket address chan...
CVE-2024-57973MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 3...
CVE-2024-57953MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rtc: tps6594: Fix integer overflow on 32bit systems...
CVE-2024-57040CRITICAL9.8TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a ...
CVE-2024-55581HIGH7.4When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-...
CVE-2024-53573CRITICAL9.8Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints ...
CVE-2024-57423MEDIUM6.1A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary co...
CVE-2024-50696HIGH7.5SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a speci...
CVE-2024-50693CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50691HIGH7.4SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app expli...
CVE-2024-50689CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50688CRITICAL9.8SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regar...
CVE-2024-50687CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50686CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50685CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v...
CVE-2024-50684MEDIUM6.5SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient ...
CVE-2024-53427HIGH8.1decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha...
CVE-2024-46226MEDIUM4.8A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary Jav...
CVE-2024-52925MEDIUM6.8In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unl...
CVE-2024-6810MEDIUM4.4The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin...
CVE-2024-47053HIGH7.7This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c...
CVE-2024-47051CRITICAL9.9This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili...
CVE-2024-39441HIGH8.4In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no ...
CVE-2024-13803MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2024-13678MEDIUM6.1The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now