2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20830 | MEDIUM | 5.3 | 0.1% | Mar 5, 2024 | Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock sett... |
| CVE-2024-20829 | MEDIUM | 5.3 | 0.3% | Mar 5, 2024 | Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers t... |
| CVE-2024-22383 | MEDIUM | 6.2 | 0.2% | Mar 5, 2024 | Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Seri... |
| CVE-2024-21838 | MEDIUM | 5.4 | 0.3% | Mar 5, 2024 | Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Cent... |
| CVE-2024-21815 | MEDIUM | 6.5 | 0.3% | Mar 5, 2024 | Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are access... |
| CVE-2024-22188 | HIGH | 7.2 | 2.0% | Mar 5, 2024 | TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell co... |
| CVE-2024-1782 | MEDIUM | 6.1 | 0.4% | Mar 5, 2024 | The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' param... |
| CVE-2024-1769 | MEDIUM | 5.3 | 0.6% | Mar 5, 2024 | The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14... |
| CVE-2024-1731 | HIGH | 8.8 | 0.9% | Mar 5, 2024 | The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu... |
| CVE-2024-1478 | MEDIUM | 5.3 | 0.5% | Mar 5, 2024 | The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2024-1381 | MEDIUM | 6.5 | 0.5% | Mar 5, 2024 | The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Info... |
| CVE-2024-1285 | MEDIUM | 6.5 | 0.4% | Mar 5, 2024 | The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2024-1178 | MEDIUM | 5.3 | 0.4% | Mar 5, 2024 | The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2024-1095 | MEDIUM | 5.3 | 0.5% | Mar 5, 2024 | The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2024-1093 | MEDIUM | 5.3 | 0.4% | Mar 5, 2024 | The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2024-1088 | MEDIUM | 5.3 | 0.6% | Mar 5, 2024 | The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2024-0825 | HIGH | 8.8 | 0.9% | Mar 5, 2024 | The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-0698 | MEDIUM | 5.4 | 0.4% | Mar 5, 2024 | The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointmen... |
| CVE-2024-25269 | HIGH | 7.5 | 0.7% | Mar 5, 2024 | libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a de... |
| CVE-2024-27718 | HIGH | 7.8 | 1.1% | Mar 5, 2024 | SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s... |
| CVE-2024-25731 | HIGH | 7.5 | 0.5% | Mar 5, 2024 | The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can ... |
| CVE-2024-25164 | HIGH | 7.5 | 0.9% | Mar 5, 2024 | iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files... |
| CVE-2024-1936 | HIGH | 7.5 | 0.7% | Mar 4, 2024 | The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email mess... |
| CVE-2024-2168 | HIGH | 7.2 | 0.6% | Mar 4, 2024 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit... |
| CVE-2024-1319 | MEDIUM | 4.3 | 0.5% | Mar 4, 2024 | The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from lea... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now