2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6626MEDIUM5.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized...
CVE-2024-10543MEDIUM4.3The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-10535MEDIUM5.3The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-9934MEDIUM6.1The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back...
CVE-2024-7879MEDIUM4.8The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-49409MEDIUM6.7Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local a...
CVE-2024-49408MEDIUM6.7Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to writ...
CVE-2024-49407MEDIUM4.6Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multip...
CVE-2024-49406MEDIUM4.4Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to mo...
CVE-2024-49405MEDIUM4.6Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access...
CVE-2024-49404MEDIUM4.6Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7....
CVE-2024-49403MEDIUM4.6Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access record...
CVE-2024-49402MEDIUM4.6Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across mu...
CVE-2024-34681MEDIUM6.6Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local perm...
CVE-2024-34680MEDIUM5.5Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to...
CVE-2024-34675MEDIUM4.6Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to u...
CVE-2024-34674MEDIUM4.6Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across mult...
CVE-2024-34673MEDIUM5.5Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial...
CVE-2024-10647MEDIUM6.1The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-47464MEDIUM6.8An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulner...
CVE-2024-10084MEDIUM4.3The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all ve...
CVE-2024-51752MEDIUM5.5The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut...
CVE-2024-51493MEDIUM6.5OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10....
CVE-2024-50335MEDIUM5.4SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish K...
CVE-2024-49773MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input val...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now