2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30864 | MEDIUM | 6.3 | 0.3% | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php. |
| CVE-2024-26655 | MEDIUM | 5.5 | 0.3% | Apr 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk o... |
| CVE-2024-30872 | MEDIUM | 5.1 | 0.3% | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php. |
| CVE-2024-3130 | MEDIUM | 5.7 | 0.1% | Apr 1, 2024 | Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized... |
| CVE-2024-25080 | MEDIUM | 4.7 | 0.3% | Apr 1, 2024 | WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer. |
| CVE-2024-2278 | MEDIUM | 6.1 | 0.4% | Apr 1, 2024 | Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high... |
| CVE-2024-2263 | MEDIUM | 4.8 | 0.4% | Apr 1, 2024 | Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, l... |
| CVE-2024-2262 | MEDIUM | 4.7 | 0.2% | Apr 1, 2024 | Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make ... |
| CVE-2024-1526 | MEDIUM | 5.3 | 0.5% | Apr 1, 2024 | The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before ... |
| CVE-2024-20055 | MEDIUM | 6.3 | 0.1% | Apr 1, 2024 | In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local informatio... |
| CVE-2024-20054 | MEDIUM | 6.6 | 0.3% | Apr 1, 2024 | In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation ... |
| CVE-2024-20052 | MEDIUM | 4.4 | 0.1% | Apr 1, 2024 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information... |
| CVE-2024-20050 | MEDIUM | 4.4 | 0.1% | Apr 1, 2024 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information... |
| CVE-2024-20049 | MEDIUM | 4.4 | 0.1% | Apr 1, 2024 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information... |
| CVE-2024-20048 | MEDIUM | 6.2 | 0.1% | Apr 1, 2024 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information... |
| CVE-2024-20047 | MEDIUM | 5.4 | 0.2% | Apr 1, 2024 | In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disc... |
| CVE-2024-20046 | MEDIUM | 6.6 | 0.3% | Apr 1, 2024 | In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation ... |
| CVE-2024-20044 | MEDIUM | 6.6 | 0.3% | Apr 1, 2024 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2024-20043 | MEDIUM | 6.6 | 0.2% | Apr 1, 2024 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2024-20042 | MEDIUM | 6.6 | 0.3% | Apr 1, 2024 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2024-20041 | MEDIUM | 4.4 | 0.2% | Apr 1, 2024 | In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo... |
| CVE-2024-31033 | MEDIUM | 6.8 | 0.8% | Apr 1, 2024 | JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a st... |
| CVE-2024-28895 | MEDIUM | 6.1 | 0.3% | Apr 1, 2024 | 'Yahoo! JAPAN' App for Android v2.3.1 to v3.161.1 and 'Yahoo! JAPAN' App for iOS v3.2.2 to v4.109.0 contain a cross-site... |
| CVE-2024-27609 | MEDIUM | 6.5 | 0.5% | Apr 1, 2024 | Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel. |
| CVE-2024-31104 | MEDIUM | 6.5 | 0.3% | Mar 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GetResponse GetRes... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now