2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31127HIGH7.3An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker t...
CVE-2024-45655MEDIUM5.5IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to i...
CVE-2024-12718MEDIUM5.3Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar...
CVE-2024-54189HIGH7.8A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b...
CVE-2024-52561HIGH7.8A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b...
CVE-2024-36486HIGH7.8A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto...
CVE-2024-53026HIGH8.2Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021HIGH8.2Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020HIGH8.2Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53019HIGH8.2Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing so...
CVE-2024-53018MEDIUM6.6Memory corruption may occur while processing the OIS packet parser.
CVE-2024-53017MEDIUM6.6Memory corruption while handling test pattern generator IOCTL command.
CVE-2024-53016MEDIUM6.6Memory corruption while processing I2C settings in Camera driver.
CVE-2024-53015MEDIUM6.6Memory corruption while processing IOCTL command to handle buffers associated with a session.
CVE-2024-53013MEDIUM6.6Memory corruption may occur while processing voice call registration with user.
CVE-2024-53010HIGH7.8Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-8008MEDIUM5.2A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encodin...
CVE-2024-7074MEDIUM6.8An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP...
CVE-2024-7073MEDIUM6.5A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in ...
CVE-2024-3509MEDIUM4.3A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insu...
CVE-2024-1440MEDIUM6.1An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in...
CVE-2024-57459HIGH7.3A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds ...
CVE-2024-40114MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an ...
CVE-2024-40113MEDIUM6.5Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.
CVE-2024-40112MEDIUM5.9A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now