2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20860 | LOW | 3.3 | 0.1% | May 7, 2024 | Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows lo... |
| CVE-2024-20859 | MEDIUM | 5.5 | 0.2% | May 7, 2024 | Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pi... |
| CVE-2024-20858 | MEDIUM | 5.5 | 0.2% | May 7, 2024 | Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 ... |
| CVE-2024-20857 | MEDIUM | 5.5 | 0.2% | May 7, 2024 | Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows loc... |
| CVE-2024-20856 | MEDIUM | 4.3 | 0.3% | May 7, 2024 | Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to acce... |
| CVE-2024-20855 | LOW | 2.4 | 0.2% | May 7, 2024 | Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attacker... |
| CVE-2024-20821 | MEDIUM | 4.4 | 0.2% | May 7, 2024 | A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode... |
| CVE-2024-2913 | MEDIUM | 6.5 | 0.3% | May 7, 2024 | A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite ... |
| CVE-2024-29941 | HIGH | 8 | 0.1% | May 6, 2024 | Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create ... |
| CVE-2024-30973 | HIGH | 8.8 | 0.9% | May 6, 2024 | An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code... |
| CVE-2024-34534 | HIGH | 7.3 | 0.5% | May 6, 2024 | A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.... |
| CVE-2024-34533 | HIGH | 7.3 | 0.5% | May 6, 2024 | A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x be... |
| CVE-2024-34532 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allow... |
| CVE-2024-34413 | MEDIUM | 5.9 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Sto... |
| CVE-2024-28725 | HIGH | 7.1 | 0.4% | May 6, 2024 | Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carous... |
| CVE-2024-1695 | MEDIUM | 5.7 | 0.2% | May 6, 2024 | A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC ... |
| CVE-2024-4568 | MEDIUM | 5.5 | 0.2% | May 6, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. |
| CVE-2024-33908 | MEDIUM | 5.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0. |
| CVE-2024-33907 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from... |
| CVE-2024-33602 | HIGH | 7.4 | 0.4% | May 6, 2024 | nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache ... |
| CVE-2024-33601 | HIGH | 7.3 | 1.1% | May 6, 2024 | nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup ... |
| CVE-2024-33600 | MEDIUM | 5.9 | 1.2% | May 6, 2024 | nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-f... |
| CVE-2024-33599 | HIGH | 8.1 | 1.3% | May 6, 2024 | nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhau... |
| CVE-2024-33576 | MEDIUM | 6.5 | 0.5% | May 6, 2024 | Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10. |
| CVE-2024-33570 | HIGH | 8.8 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now