2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53015MEDIUM6.6Memory corruption while processing IOCTL command to handle buffers associated with a session.
CVE-2024-53013MEDIUM6.6Memory corruption may occur while processing voice call registration with user.
CVE-2024-53010HIGH7.8Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-8008MEDIUM5.2A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encodin...
CVE-2024-7074MEDIUM6.8An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP...
CVE-2024-7073MEDIUM6.5A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in ...
CVE-2024-3509MEDIUM4.3A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insu...
CVE-2024-1440MEDIUM6.1An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in...
CVE-2024-57459HIGH7.3A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds ...
CVE-2024-40114MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an ...
CVE-2024-40113MEDIUM6.5Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.
CVE-2024-40112MEDIUM5.9A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, wh...
CVE-2024-54028HIGH7.8An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra...
CVE-2024-52035HIGH7.8An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. ...
CVE-2024-48877HIGH7.8A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers...
CVE-2024-57783HIGH8.1The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM outpu...
CVE-2024-12168HIGH7.8Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-11857HIGH8.5Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can creat...
CVE-2024-42191CRITICAL9.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker ...
CVE-2024-42190CRITICAL9.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ...
CVE-2024-23589MEDIUM6.8Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dic...
CVE-2024-13917HIGH8.3An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-13916MEDIUM6.9An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-13915MEDIUM6.9Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preload...
CVE-2024-7097MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now