2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1901MEDIUM4.3Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authe...
CVE-2024-1900MEDIUM5.5Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier a...
CVE-2024-1898MEDIUM4.3Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privilege...
CVE-2024-2179MEDIUM4.8Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insuff...
CVE-2024-25615MEDIUM5.3 An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol ...
CVE-2024-22253MEDIUM6.7VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious acto...
CVE-2024-22252MEDIUM6.7VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious acto...
CVE-2024-27931MEDIUM6.5Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in...
CVE-2024-27564MEDIUM6.5pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec...
CVE-2024-27563MEDIUM5.3A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the a...
CVE-2024-27627MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to exe...
CVE-2024-27625MEDIUM4.8CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manag...
CVE-2024-27623MEDIUM5.9CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within t...
CVE-2024-2188MEDIUM6.1Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. ...
CVE-2024-26337MEDIUM4.3swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.
CVE-2024-26335MEDIUM5.5swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-hist...
CVE-2024-26334MEDIUM6.2swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib...
CVE-2024-26333MEDIUM5.5swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/s...
CVE-2024-20833MEDIUM6.4Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local a...
CVE-2024-20841MEDIUM5.5Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to acc...
CVE-2024-20839MEDIUM4.6Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 ...
CVE-2024-20837MEDIUM5.3Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allow...
CVE-2024-20836MEDIUM5.5Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local att...
CVE-2024-20832MEDIUM6.7Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execut...
CVE-2024-20831MEDIUM6.7Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now