2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20860LOW3.3Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows lo...
CVE-2024-20859MEDIUM5.5Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pi...
CVE-2024-20858MEDIUM5.5Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 ...
CVE-2024-20857MEDIUM5.5Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows loc...
CVE-2024-20856MEDIUM4.3Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to acce...
CVE-2024-20855LOW2.4Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attacker...
CVE-2024-20821MEDIUM4.4A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode...
CVE-2024-2913MEDIUM6.5A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite ...
CVE-2024-29941HIGH8Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create ...
CVE-2024-30973HIGH8.8An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code...
CVE-2024-34534HIGH7.3A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0....
CVE-2024-34533HIGH7.3A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x be...
CVE-2024-34532CRITICAL9.8A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allow...
CVE-2024-34413MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Sto...
CVE-2024-28725HIGH7.1Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carous...
CVE-2024-1695MEDIUM5.7A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC ...
CVE-2024-4568MEDIUM5.5In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
CVE-2024-33908MEDIUM5.3Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.
CVE-2024-33907MEDIUM5.3Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from...
CVE-2024-33602HIGH7.4nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache ...
CVE-2024-33601HIGH7.3nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup ...
CVE-2024-33600MEDIUM5.9nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-f...
CVE-2024-33599HIGH8.1nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhau...
CVE-2024-33576MEDIUM6.5Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10.
CVE-2024-33570HIGH8.8Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now