2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21460 | MEDIUM | 6.5 | 0.1% | Jul 1, 2024 | Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space. |
| CVE-2024-6050 | MEDIUM | 6.1 | 0.8% | Jul 1, 2024 | Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflec... |
| CVE-2024-38953 | MEDIUM | 6.1 | 0.3% | Jul 1, 2024 | phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_co... |
| CVE-2024-39853 | MEDIUM | 6.5 | 0.5% | Jul 1, 2024 | adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerabilit... |
| CVE-2024-39018 | MEDIUM | 6.3 | 0.4% | Jul 1, 2024 | harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This v... |
| CVE-2024-39002 | MEDIUM | 6.3 | 0.5% | Jul 1, 2024 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerabi... |
| CVE-2024-39001 | MEDIUM | 6.3 | 0.8% | Jul 1, 2024 | ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. T... |
| CVE-2024-39000 | MEDIUM | 6.5 | 0.4% | Jul 1, 2024 | adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerabili... |
| CVE-2024-38997 | MEDIUM | 6.5 | 0.5% | Jul 1, 2024 | adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vu... |
| CVE-2024-38990 | MEDIUM | 6.3 | 0.5% | Jul 1, 2024 | Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability ... |
| CVE-2024-38987 | MEDIUM | 6.3 | 0.5% | Jul 1, 2024 | aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability ... |
| CVE-2024-39430 | MEDIUM | 6.2 | 0.1% | Jul 1, 2024 | In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-39429 | MEDIUM | 6.2 | 0.1% | Jul 1, 2024 | In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-39428 | MEDIUM | 4.4 | 0.1% | Jul 1, 2024 | In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-39427 | MEDIUM | 4.4 | 0.1% | Jul 1, 2024 | In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-6130 | MEDIUM | 4.8 | 0.4% | Jul 1, 2024 | The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-4934 | MEDIUM | 5.5 | 0.4% | Jul 1, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields bef... |
| CVE-2024-3122 | MEDIUM | 4.9 | 0.6% | Jul 1, 2024 | CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remo... |
| CVE-2024-38480 | MEDIUM | 4 | 0.2% | Jul 1, 2024 | "Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may ... |
| CVE-2024-20081 | MEDIUM | 6.7 | 0.2% | Jul 1, 2024 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esca... |
| CVE-2024-20079 | MEDIUM | 6.7 | 0.2% | Jul 1, 2024 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esca... |
| CVE-2024-6418 | MEDIUM | 5.3 | 0.5% | Jun 30, 2024 | A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unk... |
| CVE-2024-28794 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2024-31898 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypa... |
| CVE-2024-28797 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now