2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-42831MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex...
CVE-2024-46300MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-46040MEDIUM6.5IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation...
CVE-2024-45932MEDIUM4.8Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz...
CVE-2024-28710MEDIUM6.1Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code ...
CVE-2024-28709MEDIUM6.1Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code...
CVE-2024-9574MEDIUM6.5SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could a...
CVE-2024-9573MEDIUM6.5SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which cou...
CVE-2024-9572MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan...
CVE-2024-9571MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan...
CVE-2024-45933MEDIUM6.6OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the...
CVE-2024-46325MEDIUM5.5TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.
CVE-2024-45153MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-42027MEDIUM6.7The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to ...
CVE-2024-38425MEDIUM6.1Information disclosure while sending implicit broadcast containing APP launch information.
CVE-2024-23379MEDIUM6.7Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
CVE-2024-23378MEDIUM6.7Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
CVE-2024-23376MEDIUM6.7Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IO...
CVE-2024-23375MEDIUM6.7Memory corruption during the network scan request.
CVE-2024-23374MEDIUM6.7Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to...
CVE-2024-23370MEDIUM6.7Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process...
CVE-2024-47344MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affect...
CVE-2024-20102MEDIUM4.9In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote infor...
CVE-2024-20099MEDIUM6.7In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...
CVE-2024-20098MEDIUM6.7In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now