2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22385MEDIUM4.4Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read an...
CVE-2024-22168MEDIUM5.9A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found ...
CVE-2024-38903MEDIUM4.1H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
CVE-2024-38897MEDIUM5.3WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
CVE-2024-38896MEDIUM5.3WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.
CVE-2024-38895MEDIUM5.3WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
CVE-2024-38894MEDIUM5.3WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.
CVE-2024-38892MEDIUM6.5An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh compon...
CVE-2024-37681MEDIUM6.5An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote atta...
CVE-2024-37678MEDIUM5.3Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows...
CVE-2024-34312MEDIUM6.1Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2024-37732MEDIUM6.1Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a craft...
CVE-2024-37680MEDIUM6.1Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows ...
CVE-2024-37679MEDIUM6.1Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows...
CVE-2024-6104MEDIUM5.5go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryable...
CVE-2024-38369MEDIUM4.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of ...
CVE-2024-33881MEDIUM5.3An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD...
CVE-2024-33880MEDIUM5.3An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathname...
CVE-2024-6285MEDIUM6.7Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image rang...
CVE-2024-39292MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering ...
CVE-2024-38663MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from resetting io s...
CVE-2024-37825MEDIUM5.4An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2...
CVE-2024-37026MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Only use reserved BCS instances for usm mig...
CVE-2024-37021MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcou...
CVE-2024-36479MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fpga: bridge: add owner module and take its refcoun...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now