2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4583MEDIUM5.3A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulner...
CVE-2024-4582HIGH7.3A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknow...
CVE-2024-4346CRITICAL9.1The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and ...
CVE-2024-4345CRITICAL9.8The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ...
CVE-2024-3759HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.
CVE-2024-3758HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer over...
CVE-2024-3757MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.
CVE-2024-31078MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.
CVE-2024-27217HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2024-23808HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2024-4186CRITICAL9.8The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. ...
CVE-2024-3628LOW3.8The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high p...
CVE-2024-22472HIGH8.1 A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Re...
CVE-2024-20872LOW3.3Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attack...
CVE-2024-20871MEDIUM4.6Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to part...
CVE-2024-20870MEDIUM5.5Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows loc...
CVE-2024-20869MEDIUM5.5Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to byp...
CVE-2024-20868HIGH7.1Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung N...
CVE-2024-20867MEDIUM5.5Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access...
CVE-2024-20866MEDIUM6.6Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip act...
CVE-2024-20865MEDIUM6.8Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
CVE-2024-20864MEDIUM5.5Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to mon...
CVE-2024-20863MEDIUM6.7Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to ex...
CVE-2024-20862MEDIUM6.7Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary...
CVE-2024-20861MEDIUM6.7Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause me...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now