2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49848MEDIUM6.7Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
CVE-2024-45556MEDIUM6.5Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
CVE-2024-45551MEDIUM6.2Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verifi...
CVE-2024-45544MEDIUM6.6Memory corruption while processing IOCTL calls to add route entry in the HW.
CVE-2024-45543MEDIUM6.6Memory corruption while accessing MSM channel map and mixer functions.
CVE-2024-45540MEDIUM6.6Memory corruption while invoking IOCTL map buffer request from userspace.
CVE-2024-43046MEDIUM5.5There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-58133MEDIUM4In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarti...
CVE-2024-58132MEDIUM4In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal...
CVE-2024-56370MEDIUM6.5Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograph...
CVE-2024-52322MEDIUM5.5WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt...
CVE-2024-58036MEDIUM5.5Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt...
CVE-2024-57868MEDIUM5.5Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographica...
CVE-2024-57835MEDIUM5.5Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values.  String::Random defaults to Perl's bui...
CVE-2024-13898MEDIUM4.4The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl...
CVE-2024-47217MEDIUM6.5An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated ...
CVE-2024-9416MEDIUM5.4The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc...
CVE-2024-13673MEDIUM6.4The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s...
CVE-2024-56476MEDIUM5.3IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a...
CVE-2024-56475MEDIUM5.4IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authent...
CVE-2024-56341MEDIUM5.4IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth...
CVE-2024-13637MEDIUM6.5The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-12410MEDIUM4.9The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi...
CVE-2024-45700MEDIUM6.5Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send special...
CVE-2024-45699MEDIUM5.4The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl param...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now