2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-56959MEDIUM6.5An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information vi...
CVE-2024-56957MEDIUM6.5An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive use...
CVE-2024-56955MEDIUM6.5An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user inf...
CVE-2024-56954MEDIUM6.5An issue in Beijing Baidu Netcom Science & Technology Co Ltd Haokan Video iOS 7.70.0 allows attackers to access sensitiv...
CVE-2024-56953MEDIUM6.5An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information v...
CVE-2024-56952MEDIUM6.5An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to acc...
CVE-2024-56951MEDIUM6.5An issue in Hangzhou Bobo Technology Co Ltd UU Game Booster iOS 10.6.13 allows attackers to access sensitive user inform...
CVE-2024-56950MEDIUM6.5An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via...
CVE-2024-56949MEDIUM6.5An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access s...
CVE-2024-56948MEDIUM6.5An issue in KuGou Technology CO. LTD KuGou Music iOS v20.0.0 allows attackers to access sensitive user information via s...
CVE-2024-56947MEDIUM6.5An issue in Xiamen Meitu Technology Co., Ltd. BeautyCam iOS v12.3.60 allows attackers to access sensitive user informati...
CVE-2024-26317MEDIUM6.1In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacob...
CVE-2024-57272MEDIUM6.1SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS).
CVE-2024-48417MEDIUM5.2Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via ...
CVE-2024-45598MEDIUM4.9Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Po...
CVE-2024-37527MEDIUM5.4IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated ...
CVE-2024-22316MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perfo...
CVE-2024-11348MEDIUM5.3Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through manipulation of return GET requ...
CVE-2024-55931MEDIUM6.5Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is...
CVE-2024-12345MEDIUM6.7A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknow...
CVE-2024-52012MEDIUM5.4Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary fil...
CVE-2024-43445MEDIUM5.4A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-O...
CVE-2024-13117MEDIUM6.5The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and ...
CVE-2024-13095MEDIUM4.8The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL st...
CVE-2024-12774MEDIUM6.5The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now