2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12117 | MEDIUM | 5.4 | 0.3% | Jan 22, 2025 | The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-12879 | MEDIUM | 4.3 | 0.3% | Jan 22, 2025 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-11218 | HIGH | 8.6 | 0.4% | Jan 22, 2025 | A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a... |
| CVE-2024-13590 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' short... |
| CVE-2024-13584 | MEDIUM | 5.4 | 0.3% | Jan 22, 2025 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-13426 | MEDIUM | 5.3 | 0.5% | Jan 22, 2025 | The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2... |
| CVE-2024-13091 | CRITICAL | 9.8 | 0.8% | Jan 22, 2025 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
| CVE-2024-49749 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remot... |
| CVE-2024-49748 | CRITICAL | 9.8 | 0.4% | Jan 21, 2025 | In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflo... |
| CVE-2024-49747 | CRITICAL | 9.8 | 0.5% | Jan 21, 2025 | In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the cod... |
| CVE-2024-49745 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to ... |
| CVE-2024-49744 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit... |
| CVE-2024-49742 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac... |
| CVE-2024-49738 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege... |
| CVE-2024-49737 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities ... |
| CVE-2024-49736 | MEDIUM | 5.5 | 0.1% | Jan 21, 2025 | In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo... |
| CVE-2024-49735 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul... |
| CVE-2024-49734 | HIGH | 7.5 | 0.3% | Jan 21, 2025 | In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic... |
| CVE-2024-49733 | MEDIUM | 5.5 | 0.1% | Jan 21, 2025 | In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to ... |
| CVE-2024-49732 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c... |
| CVE-2024-49724 | HIGH | 7 | 0.1% | Jan 21, 2025 | In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected ... |
| CVE-2024-43771 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2024-43770 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co... |
| CVE-2024-43765 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou... |
| CVE-2024-43763 | MEDIUM | 6.5 | 0.1% | Jan 21, 2025 | In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now