2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11133MEDIUM5.3The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2024-11132MEDIUM5.4The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl...
CVE-2024-57238HIGH7.3Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The ...
CVE-2024-57237MEDIUM6.3Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp...
CVE-2024-57004MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici...
CVE-2024-50656MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-12510MEDIUM6.7If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T...
CVE-2024-57967MEDIUM4.2PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ...
CVE-2024-57362——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation d...
CVE-2024-57175MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ...
CVE-2024-56161HIGH7.2Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri...
CVE-2024-54840MEDIUM6.1PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address...
CVE-2024-53943MEDIUM6.1An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln...
CVE-2024-53942MEDIUM4.8An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln...
CVE-2024-36437MEDIUM6.5The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any insta...
CVE-2024-55456MEDIUM6.5lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
CVE-2024-49843HIGH7.8Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
CVE-2024-49840HIGH7.8Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
CVE-2024-49839CRITICAL9.8Memory corruption during management frame processing due to mismatch in T2LM info element.
CVE-2024-49838HIGH7.5Information disclosure while parsing the OCI IE with invalid length.
CVE-2024-49837HIGH7.8Memory corruption while reading CPU state data during guest VM suspend.
CVE-2024-49834HIGH7.8Memory corruption while power-up or power-down sequence of the camera sensor.
CVE-2024-49833HIGH7.8Memory corruption can occur in the camera when an invalid CID is used.
CVE-2024-49832HIGH7.8Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
CVE-2024-45584HIGH7.8Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now