2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49848 | MEDIUM | 6.7 | 0.1% | Apr 7, 2025 | Memory corruption while processing multiple IOCTL calls from HLOS to DSP. |
| CVE-2024-45556 | MEDIUM | 6.5 | 0.1% | Apr 7, 2025 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. |
| CVE-2024-45551 | MEDIUM | 6.2 | 0.1% | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verifi... |
| CVE-2024-45544 | MEDIUM | 6.6 | 0.1% | Apr 7, 2025 | Memory corruption while processing IOCTL calls to add route entry in the HW. |
| CVE-2024-45543 | MEDIUM | 6.6 | 0.1% | Apr 7, 2025 | Memory corruption while accessing MSM channel map and mixer functions. |
| CVE-2024-45540 | MEDIUM | 6.6 | 0.1% | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. |
| CVE-2024-43046 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
| CVE-2024-58133 | MEDIUM | 4 | 0.2% | Apr 6, 2025 | In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarti... |
| CVE-2024-58132 | MEDIUM | 4 | 0.2% | Apr 6, 2025 | In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal... |
| CVE-2024-56370 | MEDIUM | 6.5 | 0.3% | Apr 5, 2025 | Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograph... |
| CVE-2024-52322 | MEDIUM | 5.5 | 0.3% | Apr 5, 2025 | WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt... |
| CVE-2024-58036 | MEDIUM | 5.5 | 0.2% | Apr 5, 2025 | Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt... |
| CVE-2024-57868 | MEDIUM | 5.5 | 0.3% | Apr 5, 2025 | Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographica... |
| CVE-2024-57835 | MEDIUM | 5.5 | 0.2% | Apr 5, 2025 | Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's bui... |
| CVE-2024-13898 | MEDIUM | 4.4 | 0.2% | Apr 4, 2025 | The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl... |
| CVE-2024-47217 | MEDIUM | 6.5 | 0.3% | Apr 3, 2025 | An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated ... |
| CVE-2024-9416 | MEDIUM | 5.4 | 0.2% | Apr 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc... |
| CVE-2024-13673 | MEDIUM | 6.4 | 0.3% | Apr 3, 2025 | The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s... |
| CVE-2024-56476 | MEDIUM | 5.3 | 0.3% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a... |
| CVE-2024-56475 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authent... |
| CVE-2024-56341 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth... |
| CVE-2024-13637 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-12410 | MEDIUM | 4.9 | 0.4% | Apr 2, 2025 | The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi... |
| CVE-2024-45700 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send special... |
| CVE-2024-45699 | MEDIUM | 5.4 | 0.3% | Apr 2, 2025 | The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl param... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now