2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6626 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized... |
| CVE-2024-10543 | MEDIUM | 4.3 | 0.3% | Nov 6, 2024 | The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2024-10535 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-9934 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back... |
| CVE-2024-7879 | MEDIUM | 4.8 | 0.3% | Nov 6, 2024 | The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-49409 | MEDIUM | 6.7 | 0.1% | Nov 6, 2024 | Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local a... |
| CVE-2024-49408 | MEDIUM | 6.7 | 0.1% | Nov 6, 2024 | Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to writ... |
| CVE-2024-49407 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multip... |
| CVE-2024-49406 | MEDIUM | 4.4 | 0.1% | Nov 6, 2024 | Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to mo... |
| CVE-2024-49405 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access... |
| CVE-2024-49404 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.... |
| CVE-2024-49403 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access record... |
| CVE-2024-49402 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across mu... |
| CVE-2024-34681 | MEDIUM | 6.6 | 0.1% | Nov 6, 2024 | Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local perm... |
| CVE-2024-34680 | MEDIUM | 5.5 | 0.1% | Nov 6, 2024 | Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to... |
| CVE-2024-34675 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to u... |
| CVE-2024-34674 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across mult... |
| CVE-2024-34673 | MEDIUM | 5.5 | 0.1% | Nov 6, 2024 | Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial... |
| CVE-2024-10647 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-... |
| CVE-2024-47464 | MEDIUM | 6.8 | 0.9% | Nov 5, 2024 | An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulner... |
| CVE-2024-10084 | MEDIUM | 4.3 | 0.3% | Nov 5, 2024 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all ve... |
| CVE-2024-51752 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut... |
| CVE-2024-51493 | MEDIUM | 6.5 | 0.3% | Nov 5, 2024 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.... |
| CVE-2024-50335 | MEDIUM | 5.4 | 0.3% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish K... |
| CVE-2024-49773 | MEDIUM | 6.5 | 0.3% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input val... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now