2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47269 | MEDIUM | 4.9 | 0.2% | May 27, 2026 | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati... |
| CVE-2024-47268 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.... |
| CVE-2024-11399 | MEDIUM | 6.8 | 0.1% | May 27, 2026 | Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des... |
| CVE-2024-36343 | MEDIUM | 4.6 | 0.2% | May 19, 2026 | Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to... |
| CVE-2024-36332 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to... |
| CVE-2024-36345 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack... |
| CVE-2024-48519 | MEDIUM | 6.2 | 0.1% | May 13, 2026 | Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attack... |
| CVE-2024-51395 | MEDIUM | 6.2 | 0.1% | May 13, 2026 | Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a... |
| CVE-2024-51394 | MEDIUM | 5.5 | 0.1% | May 13, 2026 | Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a... |
| CVE-2024-36315 | MEDIUM | 5.7 | 0.1% | May 13, 2026 | Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten... |
| CVE-2024-54017 | MEDIUM | 6.9 | 0.3% | May 12, 2026 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve... |
| CVE-2024-0391 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker ... |
| CVE-2024-33724 | MEDIUM | 5.4 | 0.6% | May 8, 2026 | SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php. |
| CVE-2024-33722 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[]. |
| CVE-2024-30167 | MEDIUM | 6.3 | 1.1% | May 8, 2026 | /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm... |
| CVE-2024-13362 | MEDIUM | 6.1 | 0.3% | May 1, 2026 | Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in v... |
| CVE-2024-54012 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate i... |
| CVE-2024-54011 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data sup... |
| CVE-2024-58344 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ... |
| CVE-2024-58343 | MEDIUM | 4.3 | 0.2% | Apr 16, 2026 | Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d... |
| CVE-2024-4867 | MEDIUM | 5.4 | 0.2% | Apr 16, 2026 | The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p... |
| CVE-2024-10242 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. ... |
| CVE-2024-23104 | MEDIUM | 4.3 | 0.3% | Apr 14, 2026 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t... |
| CVE-2024-53828 | MEDIUM | 5.3 | 0.4% | Apr 1, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v... |
| CVE-2024-58342 | MEDIUM | 6.1 | 0.1% | Apr 1, 2026 | XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now