2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3668 | HIGH | 8.8 | 0.4% | Jun 8, 2024 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and in... |
| CVE-2024-0444 | HIGH | 8.8 | 1.6% | Jun 7, 2024 | GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2024-1694 | HIGH | 7.8 | 0.1% | Jun 7, 2024 | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass d... |
| CVE-2024-36827 | HIGH | 7.5 | 0.5% | Jun 7, 2024 | An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows atta... |
| CVE-2024-37163 | HIGH | 7.5 | 0.2% | Jun 7, 2024 | SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests ar... |
| CVE-2024-32502 | HIGH | 8.4 | 0.2% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ... |
| CVE-2024-31959 | HIGH | 7.8 | 0.2% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the vali... |
| CVE-2024-31958 | HIGH | 7.8 | 0.1% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the val... |
| CVE-2024-30162 | HIGH | 7.2 | 0.7% | Jun 7, 2024 | Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.ph... |
| CVE-2024-32503 | HIGH | 7.8 | 0.2% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ... |
| CVE-2024-36792 | HIGH | 8.2 | 0.3% | Jun 7, 2024 | An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain acce... |
| CVE-2024-36790 | HIGH | 8.8 | 0.3% | Jun 7, 2024 | Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext. |
| CVE-2024-36789 | HIGH | 8.1 | 0.4% | Jun 7, 2024 | An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to de... |
| CVE-2024-36787 | HIGH | 8.8 | 0.6% | Jun 7, 2024 | An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the admin... |
| CVE-2024-5599 | HIGH | 7.5 | 0.5% | Jun 7, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Expos... |
| CVE-2024-5734 | HIGH | 8.8 | 0.6% | Jun 7, 2024 | A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknow... |
| CVE-2024-4610 | HIGH | 7.8 | 0.8% | Jun 7, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-... |
| CVE-2024-5637 | HIGH | 8.1 | 0.8% | Jun 7, 2024 | The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on... |
| CVE-2024-5481 | HIGH | 8.8 | 0.7% | Jun 7, 2024 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all v... |
| CVE-2024-4902 | HIGH | 7.2 | 0.5% | Jun 7, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via ... |
| CVE-2024-4887 | HIGH | 7.5 | 0.6% | Jun 7, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ... |
| CVE-2024-36823 | HIGH | 7.5 | 0.8% | Jun 6, 2024 | The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible ... |
| CVE-2024-36774 | HIGH | 7.2 | 0.7% | Jun 6, 2024 | An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a ... |
| CVE-2024-24199 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c. |
| CVE-2024-24198 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now