2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22103MEDIUM5.5Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen...
CVE-2024-22102MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue sc...
CVE-2024-39143MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea...
CVE-2024-32757MEDIUM6.8Under certain circumstances unnecessary user details are provided within system logs
CVE-2024-32756MEDIUM6.8Under certain circumstances the Linux users credentials may be recovered by an authenticated user.
CVE-2024-39119MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=cl...
CVE-2024-6441MEDIUM6.3A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an un...
CVE-2024-6438MEDIUM6.5A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code...
CVE-2024-6264MEDIUM5.4The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ paramet...
CVE-2024-6099MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration ...
CVE-2024-6088MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a miss...
CVE-2024-4268MEDIUM5.4The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-6012MEDIUM4.3The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-6011MEDIUM4.8The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.descript...
CVE-2024-34601MEDIUM5.3Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows loca...
CVE-2024-34594MEDIUM5.5Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read ker...
CVE-2024-34592MEDIUM4.3Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attacke...
CVE-2024-34591MEDIUM4.3Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 all...
CVE-2024-34590MEDIUM4.3Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 all...
CVE-2024-34589MEDIUM6.5Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers...
CVE-2024-34588MEDIUM6.5Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers...
CVE-2024-34587MEDIUM6.8Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release...
CVE-2024-20899MEDIUM5.5Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows...
CVE-2024-20898MEDIUM5.5Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 all...
CVE-2024-20897MEDIUM5.5Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now