2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27564 | MEDIUM | 6.5 | 40.6% | Mar 5, 2024 | pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec... |
| CVE-2024-27563 | MEDIUM | 5.3 | 0.4% | Mar 5, 2024 | A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the a... |
| CVE-2024-27561 | HIGH | 8.1 | 0.6% | Mar 5, 2024 | A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers... |
| CVE-2024-24098 | HIGH | 7.8 | 0.4% | Mar 5, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed. |
| CVE-2024-27627 | MEDIUM | 6.1 | 0.4% | Mar 5, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to exe... |
| CVE-2024-27625 | MEDIUM | 4.8 | 0.4% | Mar 5, 2024 | CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manag... |
| CVE-2024-27623 | MEDIUM | 5.9 | 0.4% | Mar 5, 2024 | CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within t... |
| CVE-2024-27622 | HIGH | 7.2 | 2.0% | Mar 5, 2024 | A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2... |
| CVE-2024-2188 | MEDIUM | 6.1 | 1.0% | Mar 5, 2024 | Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. ... |
| CVE-2024-26339 | CRITICAL | 9.1 | 0.8% | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a. |
| CVE-2024-26337 | MEDIUM | 4.3 | 0.6% | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c. |
| CVE-2024-26335 | MEDIUM | 5.5 | 0.4% | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-hist... |
| CVE-2024-26334 | MEDIUM | 6.2 | 0.3% | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib... |
| CVE-2024-26333 | MEDIUM | 5.5 | 0.3% | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/s... |
| CVE-2024-20833 | MEDIUM | 6.4 | 0.1% | Mar 5, 2024 | Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local a... |
| CVE-2024-20841 | MEDIUM | 5.5 | 0.2% | Mar 5, 2024 | Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to acc... |
| CVE-2024-20840 | LOW | 2.4 | 0.2% | Mar 5, 2024 | Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 ... |
| CVE-2024-20839 | MEDIUM | 4.6 | 0.3% | Mar 5, 2024 | Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 ... |
| CVE-2024-20838 | HIGH | 7.8 | 0.2% | Mar 5, 2024 | Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitr... |
| CVE-2024-20837 | MEDIUM | 5.3 | 0.1% | Mar 5, 2024 | Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allow... |
| CVE-2024-20836 | MEDIUM | 5.5 | 0.2% | Mar 5, 2024 | Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local att... |
| CVE-2024-20835 | HIGH | 7.8 | 0.1% | Mar 5, 2024 | Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local atta... |
| CVE-2024-20834 | LOW | 3.3 | 0.1% | Mar 5, 2024 | The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to a... |
| CVE-2024-20832 | MEDIUM | 6.7 | 0.2% | Mar 5, 2024 | Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execut... |
| CVE-2024-20831 | MEDIUM | 6.7 | 0.2% | Mar 5, 2024 | Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now