2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33016MEDIUM6.8memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23365HIGH8.4Memory corruption while releasing shared resources in MinkSocket listener thread.
CVE-2024-23364HIGH7.5Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Eleme...
CVE-2024-23362HIGH7.1Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359HIGH8.2Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23358HIGH7.5Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-7692MEDIUM6.1The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-7691MEDIUM6.1The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthe...
CVE-2024-7690MEDIUM4.3The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could al...
CVE-2024-7354MEDIUM6.1The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leadin...
CVE-2024-8365MEDIUM6.5Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers ...
CVE-2024-7871HIGH8.7SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenti...
CVE-2024-45528MEDIUM5.4CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.
CVE-2024-45527MEDIUM6.1REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSR...
CVE-2024-43776HIGH8.8SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated us...
CVE-2024-43775HIGH8.8SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authe...
CVE-2024-43774HIGH8.8SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow...
CVE-2024-43773CRITICAL9.8SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow re...
CVE-2024-43772CRITICAL9.8SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow ...
CVE-2024-41160HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-41157HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-39816HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2024-39775HIGH7.5in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.
CVE-2024-39612MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-38386HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now