2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-43766MEDIUM6.5In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th...
CVE-2024-50337MEDIUM5.3Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to...
CVE-2024-10938MEDIUM6.5The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ...
CVE-2024-56208MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM...
CVE-2024-54222MEDIUM4.3Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr...
CVE-2024-52387MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste...
CVE-2024-51915MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo...
CVE-2024-50555MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...
CVE-2024-50452MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl...
CVE-2024-43228MEDIUM5.3Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a th...
CVE-2024-34438MEDIUM5.3Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a...
CVE-2024-31118MEDIUM6.5Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure...
CVE-2024-21961MEDIUM6Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces...
CVE-2024-36319MEDIUM6.3Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr...
CVE-2024-50618MEDIUM4.3A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all...
CVE-2024-26479MEDIUM5.3An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command...
CVE-2024-26478MEDIUM5.3An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us...
CVE-2024-36316MEDIUM5.5The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially ...
CVE-2024-56807MEDIUM5.5An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo...
CVE-2024-36311MEDIUM4.6A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t...
CVE-2024-36310MEDIUM4.6Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds...
CVE-2024-21953MEDIUM5.9Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o...
CVE-2024-54192MEDIUM5.5An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g...
CVE-2024-52334MEDIUM6.3A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not ...
CVE-2024-51451MEDIUM6.5IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now