2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20830MEDIUM5.3Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock sett...
CVE-2024-20829MEDIUM5.3Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers t...
CVE-2024-22383MEDIUM6.2 Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Seri...
CVE-2024-21838MEDIUM5.4 Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Cent...
CVE-2024-21815MEDIUM6.5 Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are access...
CVE-2024-22188HIGH7.2TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell co...
CVE-2024-1782MEDIUM6.1The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' param...
CVE-2024-1769MEDIUM5.3The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14...
CVE-2024-1731HIGH8.8The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu...
CVE-2024-1478MEDIUM5.3The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2024-1381MEDIUM6.5The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Info...
CVE-2024-1285MEDIUM6.5The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-1178MEDIUM5.3The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-1095MEDIUM5.3The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access...
CVE-2024-1093MEDIUM5.3The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2024-1088MEDIUM5.3The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2024-0825HIGH8.8The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-0698MEDIUM5.4The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointmen...
CVE-2024-25269HIGH7.5libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a de...
CVE-2024-27718HIGH7.8SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s...
CVE-2024-25731HIGH7.5The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can ...
CVE-2024-25164HIGH7.5iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files...
CVE-2024-1936HIGH7.5The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email mess...
CVE-2024-2168HIGH7.2A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit...
CVE-2024-1319MEDIUM4.3The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from lea...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now