2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26662MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix 'panel_cntl' could be null in ...
CVE-2024-26661MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add NULL test for 'timing generato...
CVE-2024-26660MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream ...
CVE-2024-26659MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xhci: handle isoc Babble and Buffer Overrun events ...
CVE-2024-26658MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bcachefs: grab s_umount only if snapshotting When ...
CVE-2024-26657MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/sched: fix null-ptr-deref in init entity The b...
CVE-2024-26656MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix use-after-free bug The bug can be ...
CVE-2024-24581HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.
CVE-2024-22180MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.
CVE-2024-22177MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.
CVE-2024-22098HIGH8.8in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after f...
CVE-2024-22092HIGH7.4in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, althoug...
CVE-2024-21834MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2024-2924MEDIUM6.4The Creative Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wid...
CVE-2024-2791MEDIUM5.4The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-1504MEDIUM4.3The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2024-1274MEDIUM5.4The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users wit...
CVE-2024-2369MEDIUM5.4The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options b...
CVE-2024-25187HIGH8.6Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sens...
CVE-2024-3160MEDIUM5.3** DISPUTED ** A vulnerability, which was classified as problematic, was found in Intelbras MHDX 1004, MHDX 1008, MHDX 1...
CVE-2024-20854LOW3.3Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, ...
CVE-2024-20853MEDIUM5.1Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attacke...
CVE-2024-20852LOW3.3Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows loc...
CVE-2024-20851MEDIUM5.5Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch a...
CVE-2024-20850MEDIUM5.5Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to acce...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now