2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34670 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to... |
| CVE-2024-34669 | HIGH | 8.8 | 0.5% | Oct 8, 2024 | Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers... |
| CVE-2024-34668 | HIGH | 8.8 | 0.5% | Oct 8, 2024 | Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers ... |
| CVE-2024-34667 | HIGH | 8.8 | 0.5% | Oct 8, 2024 | Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers ... |
| CVE-2024-34666 | HIGH | 8.8 | 0.5% | Oct 8, 2024 | Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allow... |
| CVE-2024-34665 | HIGH | 8.8 | 0.5% | Oct 8, 2024 | Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers ... |
| CVE-2024-34664 | LOW | 2.4 | 0.1% | Oct 8, 2024 | Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypas... |
| CVE-2024-34663 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory... |
| CVE-2024-34662 | HIGH | 7.8 | 0.1% | Oct 8, 2024 | Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Rel... |
| CVE-2024-9292 | MEDIUM | 6.4 | 0.3% | Oct 8, 2024 | The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions... |
| CVE-2024-9021 | MEDIUM | 5.4 | 0.4% | Oct 8, 2024 | In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to i... |
| CVE-2024-8983 | MEDIUM | 4.8 | 0.4% | Oct 8, 2024 | Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-21533 | MEDIUM | 6.5 | 0.6% | Oct 8, 2024 | All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif... |
| CVE-2024-21532 | HIGH | 7.3 | 1.2% | Oct 8, 2024 | All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user in... |
| CVE-2024-9026 | LOW | 3.3 | 0.5% | Oct 8, 2024 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configu... |
| CVE-2024-8927 | HIGH | 7.5 | 1.1% | Oct 8, 2024 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to ... |
| CVE-2024-8926 | HIGH | 8.8 | 3.7% | Oct 8, 2024 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configu... |
| CVE-2024-8925 | MEDIUM | 5.3 | 0.9% | Oct 8, 2024 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data ... |
| CVE-2024-47594 | MEDIUM | 5.4 | 0.2% | Oct 8, 2024 | SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip... |
| CVE-2024-45382 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write. |
| CVE-2024-45282 | MEDIUM | 5.3 | 0.3% | Oct 8, 2024 | Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified b... |
| CVE-2024-45278 | MEDIUM | 5.4 | 0.2% | Oct 8, 2024 | SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vul... |
| CVE-2024-45277 | MEDIUM | 4.3 | 0.6% | Oct 8, 2024 | The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability ... |
| CVE-2024-43697 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2024-43696 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now