2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55017HIGH7.5Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allow...
CVE-2024-58040CRITICAL9.1Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
CVE-2024-57412HIGH7.5An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP pa...
CVE-2024-13150CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software an...
CVE-2024-5200MEDIUM4.8The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-43192HIGH8.8IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attack...
CVE-2024-48014HIGH7.5Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticat...
CVE-2024-58241MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregiste...
CVE-2024-21935MEDIUM5Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate R...
CVE-2024-21927MEDIUM5Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain ...
CVE-2024-6429MEDIUM4.3A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain ...
CVE-2024-4598MEDIUM6.5An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich me...
CVE-2024-10246——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-13990CRITICAL9.3MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli...
CVE-2024-48851HIGH7.5Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an...
CVE-2024-25011MEDIUM5.3Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication chec...
CVE-2024-13151CRITICAL9.8CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In...
CVE-2024-48842HIGH7.3Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions
CVE-2024-13174HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web...
CVE-2024-13149CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ...
CVE-2024-12796MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT...
CVE-2024-12913HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communicat...
CVE-2024-12367HIGH8.6Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste...
CVE-2024-45434CRITICAL9.8OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo...
CVE-2024-45433MEDIUM6.5OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the B...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now