2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12082MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-10074HIGH7.8in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through ...
CVE-2024-11326MEDIUM6.1The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-47476HIGH7.8Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vuln...
CVE-2024-45106HIGH8.1Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us...
CVE-2024-12062MEDIUM4.3The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...
CVE-2024-11782MEDIUM5.4The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' short...
CVE-2024-11325MEDIUM5.2The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add...
CVE-2024-11866MEDIUM6.4The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'...
CVE-2024-11844MEDIUM4.3The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-11898MEDIUM5.4The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin...
CVE-2024-11853MEDIUM6.4The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versio...
CVE-2024-11805MEDIUM6.1The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2024-11732MEDIUM6.5The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter i...
CVE-2024-11707MEDIUM6.1The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in...
CVE-2024-11461MEDIUM6.1The Form Data Collector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in...
CVE-2024-11453MEDIUM5.4The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerab...
CVE-2024-9058MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-49421MEDIUM4.3Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in ...
CVE-2024-49420HIGH7.5Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attacke...
CVE-2024-49419MEDIUM4.3Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows...
CVE-2024-49418MEDIUM6.5Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows...
CVE-2024-49417LOW3.3Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch...
CVE-2024-49416MEDIUM5.5Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get ...
CVE-2024-49415CRITICAL9.8Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now