2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49408 | MEDIUM | 6.7 | 0.1% | Nov 6, 2024 | Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to writ... |
| CVE-2024-49407 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multip... |
| CVE-2024-49406 | MEDIUM | 4.4 | 0.1% | Nov 6, 2024 | Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to mo... |
| CVE-2024-49405 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access... |
| CVE-2024-49404 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.... |
| CVE-2024-49403 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access record... |
| CVE-2024-49402 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across mu... |
| CVE-2024-34681 | MEDIUM | 6.6 | 0.1% | Nov 6, 2024 | Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local perm... |
| CVE-2024-34680 | MEDIUM | 5.5 | 0.1% | Nov 6, 2024 | Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to... |
| CVE-2024-34675 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to u... |
| CVE-2024-34674 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across mult... |
| CVE-2024-34673 | MEDIUM | 5.5 | 0.1% | Nov 6, 2024 | Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial... |
| CVE-2024-10647 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-... |
| CVE-2024-47464 | MEDIUM | 6.8 | 0.9% | Nov 5, 2024 | An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulner... |
| CVE-2024-10084 | MEDIUM | 4.3 | 0.3% | Nov 5, 2024 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all ve... |
| CVE-2024-51752 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut... |
| CVE-2024-51493 | MEDIUM | 6.5 | 0.3% | Nov 5, 2024 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.... |
| CVE-2024-50335 | MEDIUM | 5.4 | 0.3% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish K... |
| CVE-2024-49773 | MEDIUM | 6.5 | 0.3% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input val... |
| CVE-2024-49377 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.... |
| CVE-2024-0134 | MEDIUM | 4.1 | 0.4% | Nov 5, 2024 | NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted contai... |
| CVE-2024-51739 | MEDIUM | 5.3 | 1.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, whic... |
| CVE-2024-50138 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Use raw_spinlock_t in ringbuf The function __... |
| CVE-2024-50137 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: reset: starfive: jh71x0: Fix accessing the empty me... |
| CVE-2024-50136 | MEDIUM | 5.5 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now