2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-48448MEDIUM6.1An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploadin...
CVE-2024-48343MEDIUM6.3A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id para...
CVE-2024-8036MEDIUM5.9ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exp...
CVE-2024-48743MEDIUM6.5Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parame...
CVE-2024-48654MEDIUM6.1Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2024-49757MEDIUM4.9The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Du...
CVE-2024-49378MEDIUM6.1smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox vers...
CVE-2024-10374MEDIUM5.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme...
CVE-2024-47483MEDIUM5.5Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in a...
CVE-2024-47481MEDIUM6.5Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated...
CVE-2024-47034MEDIUM5.5there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure wi...
CVE-2024-47030MEDIUM5.1Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.
CVE-2024-47029MEDIUM5.5In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible ou...
CVE-2024-47028MEDIUM4.4In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local ...
CVE-2024-47026MEDIUM5.5In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead...
CVE-2024-47025MEDIUM5.5In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could...
CVE-2024-47019MEDIUM5.5In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a miss...
CVE-2024-47018MEDIUM5.5In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This...
CVE-2024-47015MEDIUM5.5In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due t...
CVE-2024-44099MEDIUM5.5There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local informat...
CVE-2024-8666MEDIUM6.4The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-10343MEDIUM6.4The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u...
CVE-2024-10112MEDIUM6.4The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in a...
CVE-2024-10016MEDIUM6.4The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ...
CVE-2024-9630MEDIUM5.3The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now