2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38214MEDIUM6.5Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2024-38213MEDIUM6.5Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-38197MEDIUM6.5Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-38173MEDIUM6.7Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-38167MEDIUM6.5.NET and Visual Studio Information Disclosure Vulnerability
CVE-2024-38165MEDIUM6.5Windows Compressed Folder Tampering Vulnerability
CVE-2024-38161MEDIUM6.8Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2024-38155MEDIUM5.5Security Center Broker Information Disclosure Vulnerability
CVE-2024-38151MEDIUM5.5Windows Kernel Information Disclosure Vulnerability
CVE-2024-38143MEDIUM4.2Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
CVE-2024-38123MEDIUM4.4Windows Bluetooth Driver Information Disclosure Vulnerability
CVE-2024-38122MEDIUM5.5Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
CVE-2024-38118MEDIUM5.5Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
CVE-2024-41711MEDIUM6.8A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, ...
CVE-2024-41614MEDIUM4.8symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.
CVE-2024-41613MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script...
CVE-2024-21981MEDIUM5.7Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrar...
CVE-2024-36505MEDIUM5.5An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7...
CVE-2024-6384MEDIUM5.3"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifi...
CVE-2024-42740MEDIUM6.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-3913MEDIUM5.9An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable...
CVE-2024-38501MEDIUM6.1An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML c...
CVE-2024-43165MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allow...
CVE-2024-41774MEDIUM4.8IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to em...
CVE-2024-39642MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality No...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now