2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49409 | MEDIUM | 6.7 | 0.1% | Nov 6, 2024 | Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local a... |
| CVE-2024-49408 | MEDIUM | 6.7 | 0.1% | Nov 6, 2024 | Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to writ... |
| CVE-2024-49407 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multip... |
| CVE-2024-49406 | MEDIUM | 4.4 | 0.1% | Nov 6, 2024 | Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to mo... |
| CVE-2024-49405 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access... |
| CVE-2024-49404 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.... |
| CVE-2024-49403 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access record... |
| CVE-2024-49402 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across mu... |
| CVE-2024-49401 | HIGH | 7.1 | 0.2% | Nov 6, 2024 | Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privi... |
| CVE-2024-34682 | LOW | 2.4 | 0.2% | Nov 6, 2024 | Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi passw... |
| CVE-2024-34681 | MEDIUM | 6.6 | 0.1% | Nov 6, 2024 | Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local perm... |
| CVE-2024-34680 | MEDIUM | 5.5 | 0.1% | Nov 6, 2024 | Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to... |
| CVE-2024-34679 | HIGH | 7.1 | 0.1% | Nov 6, 2024 | Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone... |
| CVE-2024-34678 | HIGH | 7.8 | 0.2% | Nov 6, 2024 | Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup... |
| CVE-2024-34677 | LOW | 3.3 | 0.1% | Nov 6, 2024 | Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious a... |
| CVE-2024-34676 | HIGH | 7.3 | 0.2% | Nov 6, 2024 | Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attacker... |
| CVE-2024-34675 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to u... |
| CVE-2024-34674 | MEDIUM | 4.6 | 0.2% | Nov 6, 2024 | Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across mult... |
| CVE-2024-34673 | MEDIUM | 5.5 | 0.1% | Nov 6, 2024 | Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial... |
| CVE-2024-10647 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-... |
| CVE-2024-10028 | HIGH | 7.5 | 0.4% | Nov 6, 2024 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to S... |
| CVE-2024-51358 | CRITICAL | 9.8 | 0.9% | Nov 5, 2024 | An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the... |
| CVE-2024-51115 | CRITICAL | 9.8 | 1.7% | Nov 5, 2024 | DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability. |
| CVE-2024-48746 | CRITICAL | 9.8 | 0.7% | Nov 5, 2024 | An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the N... |
| CVE-2024-48176 | CRITICAL | 9.8 | 0.5% | Nov 5, 2024 | Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now