2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-35039LOW3.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.
CVE-2024-3823LOW2.4The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is mi...
CVE-2024-3629LOW2.4The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which co...
CVE-2024-32020LOW3.3Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local cl...
CVE-2024-34713LOW3.5sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. P...
CVE-2024-33007LOW3.5PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. I...
CVE-2024-33000LOW3.5SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalati...
CVE-2024-34218LOW3.8TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTP...
CVE-2024-34203LOW3.8TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguage...
CVE-2024-34079LOW3.7octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike ...
CVE-2024-27839LOW3.3A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iP...
CVE-2024-27837LOW3.3A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A l...
CVE-2024-27835LOW2.4This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-27803LOW2.4A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-22343LOW3.3IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the syste...
CVE-2024-29210LOW2.8A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifical...
CVE-2024-29208LOW2.2An Unverified Password Change could allow a malicious actor with API access to the device to change the system password ...
CVE-2024-29206LOW2.2An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) a...
CVE-2024-3628LOW3.8The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high p...
CVE-2024-20872LOW3.3Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attack...
CVE-2024-20860LOW3.3Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows lo...
CVE-2024-20855LOW2.4Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attacker...
CVE-2024-31636LOW3.9An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_re...
CVE-2024-3480LOW2.8An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-r...
CVE-2024-3479LOW2.8 An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterpr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now