2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-57908HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered ...
CVE-2024-57907HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in ...
CVE-2024-57906HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads8688: fix information leak in trigg...
CVE-2024-57905HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix information leak in trigg...
CVE-2024-57904HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocat...
CVE-2024-45652HIGH7.5IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could...
CVE-2024-45662HIGH7.5IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a rem...
CVE-2024-49354HIGH7.5IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Call...
CVE-2024-47106HIGH7.5IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information fro...
CVE-2024-13184HIGH7.5The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the ...
CVE-2024-57030HIGH8.1Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-52870HIGH7.1Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin...
CVE-2024-12757HIGH8.8Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker ...
CVE-2024-26155HIGH8.6All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal....
CVE-2024-26153HIGH7.4All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C...
CVE-2024-12703HIGH8.5CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an...
CVE-2024-12142HIGH8.8CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di...
CVE-2024-10497HIGH8.8CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t...
CVE-2024-13377HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi...
CVE-2024-12476HIGH8.4CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos...
CVE-2024-12399HIGH7.1CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-11425HIGH8.7CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe...
CVE-2024-13333HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-52363HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker ...
CVE-2024-34579HIGH8.5Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now