2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45655 | MEDIUM | 5.5 | 0.1% | Jun 3, 2025 | IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to i... |
| CVE-2024-12718 | MEDIUM | 5.3 | 0.6% | Jun 3, 2025 | Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar... |
| CVE-2024-53018 | MEDIUM | 6.6 | 0.1% | Jun 3, 2025 | Memory corruption may occur while processing the OIS packet parser. |
| CVE-2024-53017 | MEDIUM | 6.6 | 0.1% | Jun 3, 2025 | Memory corruption while handling test pattern generator IOCTL command. |
| CVE-2024-53016 | MEDIUM | 6.6 | 0.1% | Jun 3, 2025 | Memory corruption while processing I2C settings in Camera driver. |
| CVE-2024-53015 | MEDIUM | 6.6 | 0.1% | Jun 3, 2025 | Memory corruption while processing IOCTL command to handle buffers associated with a session. |
| CVE-2024-53013 | MEDIUM | 6.6 | 0.1% | Jun 3, 2025 | Memory corruption may occur while processing voice call registration with user. |
| CVE-2024-8008 | MEDIUM | 5.2 | 0.5% | Jun 2, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encodin... |
| CVE-2024-7074 | MEDIUM | 6.8 | 9.8% | Jun 2, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP... |
| CVE-2024-7073 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in ... |
| CVE-2024-3509 | MEDIUM | 4.3 | 0.2% | Jun 2, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insu... |
| CVE-2024-1440 | MEDIUM | 6.1 | 0.2% | Jun 2, 2025 | An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in... |
| CVE-2024-40114 | MEDIUM | 6.1 | 0.2% | Jun 2, 2025 | A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an ... |
| CVE-2024-40113 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials. |
| CVE-2024-40112 | MEDIUM | 5.9 | 0.4% | Jun 2, 2025 | A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, wh... |
| CVE-2024-23589 | MEDIUM | 6.8 | 0.1% | May 30, 2025 | Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dic... |
| CVE-2024-13916 | MEDIUM | 6.9 | 0.2% | May 30, 2025 | An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati... |
| CVE-2024-13915 | MEDIUM | 6.9 | 0.2% | May 30, 2025 | Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preload... |
| CVE-2024-7097 | MEDIUM | 4.3 | 0.5% | May 30, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which... |
| CVE-2024-7096 | MEDIUM | 5.4 | 0.6% | May 30, 2025 | A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service... |
| CVE-2024-53423 | MEDIUM | 5.6 | 0.2% | May 29, 2025 | An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafte... |
| CVE-2024-22653 | MEDIUM | 4.8 | 0.2% | May 29, 2025 | yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se... |
| CVE-2024-57338 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x... |
| CVE-2024-57337 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.10... |
| CVE-2024-57336 | MEDIUM | 6.5 | 0.2% | May 28, 2025 | Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unautho... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now