2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45655MEDIUM5.5IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to i...
CVE-2024-12718MEDIUM5.3Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar...
CVE-2024-53018MEDIUM6.6Memory corruption may occur while processing the OIS packet parser.
CVE-2024-53017MEDIUM6.6Memory corruption while handling test pattern generator IOCTL command.
CVE-2024-53016MEDIUM6.6Memory corruption while processing I2C settings in Camera driver.
CVE-2024-53015MEDIUM6.6Memory corruption while processing IOCTL command to handle buffers associated with a session.
CVE-2024-53013MEDIUM6.6Memory corruption may occur while processing voice call registration with user.
CVE-2024-8008MEDIUM5.2A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encodin...
CVE-2024-7074MEDIUM6.8An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP...
CVE-2024-7073MEDIUM6.5A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in ...
CVE-2024-3509MEDIUM4.3A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insu...
CVE-2024-1440MEDIUM6.1An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in...
CVE-2024-40114MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an ...
CVE-2024-40113MEDIUM6.5Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.
CVE-2024-40112MEDIUM5.9A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, wh...
CVE-2024-23589MEDIUM6.8Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dic...
CVE-2024-13916MEDIUM6.9An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-13915MEDIUM6.9Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preload...
CVE-2024-7097MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which...
CVE-2024-7096MEDIUM5.4A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service...
CVE-2024-53423MEDIUM5.6An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafte...
CVE-2024-22653MEDIUM4.8yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se...
CVE-2024-57338MEDIUM6.5An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x...
CVE-2024-57337MEDIUM6.5An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.10...
CVE-2024-57336MEDIUM6.5Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unautho...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now