2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27564MEDIUM6.5pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec...
CVE-2024-27563MEDIUM5.3A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the a...
CVE-2024-27561HIGH8.1A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers...
CVE-2024-24098HIGH7.8Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
CVE-2024-27627MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to exe...
CVE-2024-27625MEDIUM4.8CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manag...
CVE-2024-27623MEDIUM5.9CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within t...
CVE-2024-27622HIGH7.2A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2...
CVE-2024-2188MEDIUM6.1Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. ...
CVE-2024-26339CRITICAL9.1swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.
CVE-2024-26337MEDIUM4.3swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.
CVE-2024-26335MEDIUM5.5swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-hist...
CVE-2024-26334MEDIUM6.2swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib...
CVE-2024-26333MEDIUM5.5swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/s...
CVE-2024-20833MEDIUM6.4Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local a...
CVE-2024-20841MEDIUM5.5Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to acc...
CVE-2024-20840LOW2.4Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 ...
CVE-2024-20839MEDIUM4.6Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 ...
CVE-2024-20838HIGH7.8Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitr...
CVE-2024-20837MEDIUM5.3Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allow...
CVE-2024-20836MEDIUM5.5Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local att...
CVE-2024-20835HIGH7.8Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local atta...
CVE-2024-20834LOW3.3The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to a...
CVE-2024-20832MEDIUM6.7Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execut...
CVE-2024-20831MEDIUM6.7Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now