2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47012 | HIGH | 7.8 | 0.1% | Oct 25, 2024 | In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bound... |
| CVE-2024-44101 | HIGH | 7.5 | 0.4% | Oct 25, 2024 | there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote d... |
| CVE-2024-44100 | HIGH | 7.5 | 0.2% | Oct 25, 2024 | Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545. |
| CVE-2024-44099 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local informat... |
| CVE-2024-44098 | HIGH | 7.4 | 0.1% | Oct 25, 2024 | In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free.... |
| CVE-2024-10377 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDe... |
| CVE-2024-10376 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function a... |
| CVE-2024-8666 | MEDIUM | 6.4 | 0.3% | Oct 25, 2024 | The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-10343 | MEDIUM | 6.4 | 0.3% | Oct 25, 2024 | The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u... |
| CVE-2024-10112 | MEDIUM | 6.4 | 0.3% | Oct 25, 2024 | The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in a... |
| CVE-2024-10016 | MEDIUM | 6.4 | 0.4% | Oct 25, 2024 | The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ... |
| CVE-2024-9630 | MEDIUM | 5.3 | 0.3% | Oct 25, 2024 | The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when ... |
| CVE-2024-9628 | MEDIUM | 6.5 | 0.3% | Oct 25, 2024 | The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a ... |
| CVE-2024-9598 | HIGH | 8.8 | 0.3% | Oct 25, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio... |
| CVE-2024-47158 | MEDIUM | 5.4 | 0.2% | Oct 25, 2024 | N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary co... |
| CVE-2024-45785 | HIGH | 7.5 | 0.4% | Oct 25, 2024 | MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other use... |
| CVE-2024-10342 | MEDIUM | 5.4 | 0.3% | Oct 25, 2024 | The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in ver... |
| CVE-2024-10341 | MEDIUM | 6.5 | 0.4% | Oct 25, 2024 | The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versi... |
| CVE-2024-10150 | MEDIUM | 5.4 | 0.3% | Oct 25, 2024 | The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs sh... |
| CVE-2024-9607 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-9302 | CRITICAL | 9.8 | 0.6% | Oct 25, 2024 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalat... |
| CVE-2024-9235 | HIGH | 8.8 | 0.5% | Oct 25, 2024 | The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e... |
| CVE-2024-50583 | MEDIUM | 6.3 | 0.3% | Oct 25, 2024 | Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to impr... |
| CVE-2024-48870 | MEDIUM | 4.8 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scr... |
| CVE-2024-47801 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now