2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-30864MEDIUM6.3netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.
CVE-2024-26655MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk o...
CVE-2024-30872MEDIUM5.1netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.
CVE-2024-3130MEDIUM5.7Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized...
CVE-2024-25080MEDIUM4.7WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.
CVE-2024-2278MEDIUM6.1Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high...
CVE-2024-2263MEDIUM4.8Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, l...
CVE-2024-2262MEDIUM4.7Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make ...
CVE-2024-1526MEDIUM5.3The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before ...
CVE-2024-20055MEDIUM6.3In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local informatio...
CVE-2024-20054MEDIUM6.6In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation ...
CVE-2024-20052MEDIUM4.4In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information...
CVE-2024-20050MEDIUM4.4In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information...
CVE-2024-20049MEDIUM4.4In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information...
CVE-2024-20048MEDIUM6.2In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information...
CVE-2024-20047MEDIUM5.4In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disc...
CVE-2024-20046MEDIUM6.6In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation ...
CVE-2024-20044MEDIUM6.6In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri...
CVE-2024-20043MEDIUM6.6In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri...
CVE-2024-20042MEDIUM6.6In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri...
CVE-2024-20041MEDIUM4.4In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo...
CVE-2024-31033MEDIUM6.8JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a st...
CVE-2024-28895MEDIUM6.1'Yahoo! JAPAN' App for Android v2.3.1 to v3.161.1 and 'Yahoo! JAPAN' App for iOS v3.2.2 to v4.109.0 contain a cross-site...
CVE-2024-27609MEDIUM6.5Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel.
CVE-2024-31104MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GetResponse GetRes...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now