2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39967MEDIUM6.5Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command...
CVE-2024-36751MEDIUM6.5An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.
CVE-2024-48122MEDIUM6.7Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileg...
CVE-2024-48121MEDIUM6.5The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi...
CVE-2024-54540MEDIUM4.3The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc...
CVE-2024-54535MEDIUM4.3A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ...
CVE-2024-54470MEDIUM4.6A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPad...
CVE-2024-44136MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-40854MEDIUM5.5A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS ...
CVE-2024-57025MEDIUM6.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p...
CVE-2024-57024MEDIUM6.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute...
CVE-2024-57023MEDIUM6.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p...
CVE-2024-52783MEDIUM5.1Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execut...
CVE-2024-56295MEDIUM6.5Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con...
CVE-2024-47140MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially cr...
CVE-2024-47002MEDIUM5.4A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted H...
CVE-2024-45061MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A ...
CVE-2024-57903MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: restrict SO_REUSEPORT to inet sockets After b...
CVE-2024-57902MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_tci() vs MSG_PEEK Blamed c...
CVE-2024-57901MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEE...
CVE-2024-57897MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Correct the migration DMA map direction...
CVE-2024-57895MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: set ATTR_CTIME flags when setting mtime Dav...
CVE-2024-57893MEDIUM6.3In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix races at processing SysEx messa...
CVE-2024-57891MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix invalid irq restore in scx_ops_bypas...
CVE-2024-57890MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Prevent integer overflow issue In the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now