2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46802MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_va...
CVE-2024-46441HIGH8.8An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to the...
CVE-2024-9280CRITICAL9.8A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as c...
CVE-2024-9279MEDIUM4.8A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown...
CVE-2024-8644HIGH7.5Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipul...
CVE-2024-8643CRITICAL9.8Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects Va...
CVE-2024-8609HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Infor...
CVE-2024-8608MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Sof...
CVE-2024-8607CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software V...
CVE-2024-9278MEDIUM5.1A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue ...
CVE-2024-9277MEDIUM6.5A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unkno...
CVE-2024-9276MEDIUM5.3A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of ...
CVE-2024-9275MEDIUM6.3A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some u...
CVE-2024-9136HIGH7.5Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulner...
CVE-2024-47294HIGH7.5Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of thi...
CVE-2024-47293HIGH7.5Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affec...
CVE-2024-47292MEDIUM5.5Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect se...
CVE-2024-47291MEDIUM5.5Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerabilit...
CVE-2024-47290MEDIUM5.5Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affec...
CVE-2024-9202MEDIUM5.3In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) ...
CVE-2024-6931MEDIUM6.1The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all ver...
CVE-2024-6654MEDIUM6.8Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused ...
CVE-2024-41930MEDIUM6.1Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability i...
CVE-2024-38861HIGH7.4Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traff...
CVE-2024-39435HIGH7.8In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now