2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47269MEDIUM4.9Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati...
CVE-2024-47268MEDIUM4.9Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2....
CVE-2024-11399MEDIUM6.8Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des...
CVE-2024-36343MEDIUM4.6Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to...
CVE-2024-36332MEDIUM6.8Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to...
CVE-2024-36345MEDIUM4.6Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack...
CVE-2024-48519MEDIUM6.2Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attack...
CVE-2024-51395MEDIUM6.2Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-51394MEDIUM5.5Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-36315MEDIUM5.7Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten...
CVE-2024-54017MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve...
CVE-2024-0391MEDIUM4.3The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker ...
CVE-2024-33724MEDIUM5.4SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
CVE-2024-33722MEDIUM6.3SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
CVE-2024-30167MEDIUM6.3/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm...
CVE-2024-13362MEDIUM6.1Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in v...
CVE-2024-54012MEDIUM5.3Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate i...
CVE-2024-54011MEDIUM6.5Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data sup...
CVE-2024-58344MEDIUM6.4Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ...
CVE-2024-58343MEDIUM4.3Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d...
CVE-2024-4867MEDIUM5.4The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p...
CVE-2024-10242MEDIUM6.1The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. ...
CVE-2024-23104MEDIUM4.3An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t...
CVE-2024-53828MEDIUM5.3Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v...
CVE-2024-58342MEDIUM6.1XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now