2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49409MEDIUM6.7Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local a...
CVE-2024-49408MEDIUM6.7Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to writ...
CVE-2024-49407MEDIUM4.6Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multip...
CVE-2024-49406MEDIUM4.4Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to mo...
CVE-2024-49405MEDIUM4.6Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access...
CVE-2024-49404MEDIUM4.6Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7....
CVE-2024-49403MEDIUM4.6Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access record...
CVE-2024-49402MEDIUM4.6Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across mu...
CVE-2024-49401HIGH7.1Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privi...
CVE-2024-34682LOW2.4Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi passw...
CVE-2024-34681MEDIUM6.6Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local perm...
CVE-2024-34680MEDIUM5.5Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to...
CVE-2024-34679HIGH7.1Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone...
CVE-2024-34678HIGH7.8Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup...
CVE-2024-34677LOW3.3Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious a...
CVE-2024-34676HIGH7.3Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attacker...
CVE-2024-34675MEDIUM4.6Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to u...
CVE-2024-34674MEDIUM4.6Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across mult...
CVE-2024-34673MEDIUM5.5Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial...
CVE-2024-10647MEDIUM6.1The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-10028HIGH7.5The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to S...
CVE-2024-51358CRITICAL9.8An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the...
CVE-2024-51115CRITICAL9.8DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
CVE-2024-48746CRITICAL9.8An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the N...
CVE-2024-48176CRITICAL9.8Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now