2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49720HIGH7.8In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi...
CVE-2024-40653HIGH7.3In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba...
CVE-2024-51423MEDIUM6.1Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execut...
CVE-2024-48705MEDIUM6.5Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication ...
CVE-2024-12974MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Pr...
CVE-2024-58259HIGH8.2A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert...
CVE-2024-52284HIGH7.7Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou...
CVE-2024-12973MEDIUM4.7Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsi...
CVE-2024-12972MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Oc...
CVE-2024-28988CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,...
CVE-2024-12925HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. ...
CVE-2024-12924MEDIUM6.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing...
CVE-2024-12914MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR...
CVE-2024-32832CRITICAL9.8Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L...
CVE-2024-32589HIGH7.1Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ...
CVE-2024-46484CRITICAL9.8TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser...
CVE-2024-12923MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user ...
CVE-2024-46917HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur...
CVE-2024-46916HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys...
CVE-2024-13342CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-13987MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Se...
CVE-2024-54568MEDIUM4.3The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously ...
CVE-2024-54554MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ab...
CVE-2024-44271LOW3.3The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record th...
CVE-2024-13986HIGH8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now