2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-3668HIGH8.8The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and in...
CVE-2024-0444HIGH8.8GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2024-1694HIGH7.8Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass d...
CVE-2024-36827HIGH7.5An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows atta...
CVE-2024-37163HIGH7.5SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests ar...
CVE-2024-32502HIGH8.4An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ...
CVE-2024-31959HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the vali...
CVE-2024-31958HIGH7.8An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the val...
CVE-2024-30162HIGH7.2Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.ph...
CVE-2024-32503HIGH7.8An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ...
CVE-2024-36792HIGH8.2An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain acce...
CVE-2024-36790HIGH8.8Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
CVE-2024-36789HIGH8.1An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to de...
CVE-2024-36787HIGH8.8An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the admin...
CVE-2024-5599HIGH7.5The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Expos...
CVE-2024-5734HIGH8.8A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknow...
CVE-2024-4610HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-...
CVE-2024-5637HIGH8.1The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on...
CVE-2024-5481HIGH8.8The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all v...
CVE-2024-4902HIGH7.2The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via ...
CVE-2024-4887HIGH7.5The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ...
CVE-2024-36823HIGH7.5The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible ...
CVE-2024-36774HIGH7.2An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a ...
CVE-2024-24199HIGH7.5smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.
CVE-2024-24198HIGH7.5smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now