2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10313HIGH8.6iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malici...
CVE-2024-10295HIGH7.5A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly ...
CVE-2024-9692MEDIUM6.9VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attack...
CVE-2024-48548CRITICAL9.3The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulne...
CVE-2024-48547HIGH8.4Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to a...
CVE-2024-48546HIGH8.4Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access se...
CVE-2024-48545HIGH8.4Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access se...
CVE-2024-48544HIGH8.4Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to...
CVE-2024-48542HIGH8.4Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows att...
CVE-2024-48541HIGH8.4Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to acces...
CVE-2024-48540MEDIUM6.2Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a...
CVE-2024-48539CRITICAL9.8Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
CVE-2024-44206CRITICAL9.3An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17....
CVE-2024-44205MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 an...
CVE-2024-44185MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma...
CVE-2024-44141MEDIUM6.8The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to...
CVE-2024-40810MEDIUM5.5An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An ...
CVE-2024-10336CRITICAL9.8A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue...
CVE-2024-10335CRITICAL9.8A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. ...
CVE-2024-48538CRITICAL9.8Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sen...
CVE-2024-45031MEDIUM6.1When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made i...
CVE-2024-49702MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ...
CVE-2024-49696MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gall...
CVE-2024-49695MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP ...
CVE-2024-49693MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now