2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13073MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Ta...
CVE-2024-13071MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-...
CVE-2024-13068HIGH7.3Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: fro...
CVE-2024-13066MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - ...
CVE-2024-43166CRITICAL9.8Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef...
CVE-2024-43115HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s...
CVE-2024-13065MEDIUM6.3Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows...
CVE-2024-13064MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft My...
CVE-2024-13063MEDIUM6.8Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issu...
CVE-2024-32444CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue...
CVE-2024-49730HIGH7.8In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation...
CVE-2024-49728MEDIUM5.5In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused ...
CVE-2024-49722MEDIUM5.5In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy....
CVE-2024-49720HIGH7.8In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi...
CVE-2024-40653HIGH7.3In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba...
CVE-2024-51423MEDIUM6.1Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execut...
CVE-2024-48705MEDIUM6.5Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication ...
CVE-2024-12974MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Pr...
CVE-2024-58259HIGH8.2A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert...
CVE-2024-52284HIGH7.7Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou...
CVE-2024-12973MEDIUM4.7Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsi...
CVE-2024-12972MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Oc...
CVE-2024-28988CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,...
CVE-2024-12925HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. ...
CVE-2024-12924MEDIUM6.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now