2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47012HIGH7.8In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bound...
CVE-2024-44101HIGH7.5there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote d...
CVE-2024-44100HIGH7.5Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
CVE-2024-44099MEDIUM5.5There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local informat...
CVE-2024-44098HIGH7.4In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free....
CVE-2024-10377CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDe...
CVE-2024-10376CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function a...
CVE-2024-8666MEDIUM6.4The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-10343MEDIUM6.4The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u...
CVE-2024-10112MEDIUM6.4The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in a...
CVE-2024-10016MEDIUM6.4The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ...
CVE-2024-9630MEDIUM5.3The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when ...
CVE-2024-9628MEDIUM6.5The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a ...
CVE-2024-9598HIGH8.8The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2024-47158MEDIUM5.4N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary co...
CVE-2024-45785HIGH7.5MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other use...
CVE-2024-10342MEDIUM5.4The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in ver...
CVE-2024-10341MEDIUM6.5The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versi...
CVE-2024-10150MEDIUM5.4The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs sh...
CVE-2024-9607MEDIUM6.1The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-9302CRITICAL9.8The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalat...
CVE-2024-9235HIGH8.8The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2024-50583MEDIUM6.3Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to impr...
CVE-2024-48870MEDIUM4.8Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scr...
CVE-2024-47801MEDIUM6.1Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now