2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-56338MEDIUM4.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-...
CVE-2024-51322MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-51320MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-46663MEDIUM6.7A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
CVE-2024-33501MEDIUM6.7Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti...
CVE-2024-32123MEDIUM6.7Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan...
CVE-2024-52285MEDIUM6.9A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-...
CVE-2024-58102MEDIUM6.5An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consum...
CVE-2024-13228MEDIUM6.5The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-13853MEDIUM6.1The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13580MEDIUM4.3The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which c...
CVE-2024-13413MEDIUM6.1The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all vers...
CVE-2024-13436MEDIUM6.1The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-49823MEDIUM6.5IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of servic...
CVE-2024-22340MEDIUM6.5IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive informa...
CVE-2024-56188MEDIUM5.1there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with...
CVE-2024-56187MEDIUM6.6In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the...
CVE-2024-56186MEDIUM5.1In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This ...
CVE-2024-56185MEDIUM5.1In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to...
CVE-2024-56184MEDIUM5.1In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This co...
CVE-2024-54560MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18...
CVE-2024-54473MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An a...
CVE-2024-54469MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonom...
CVE-2024-54467MEDIUM6.5A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPa...
CVE-2024-54463MEDIUM5.5This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to acce...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now