2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34670MEDIUM5.5Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to...
CVE-2024-34669HIGH8.8Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers...
CVE-2024-34668HIGH8.8Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers ...
CVE-2024-34667HIGH8.8Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers ...
CVE-2024-34666HIGH8.8Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allow...
CVE-2024-34665HIGH8.8Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers ...
CVE-2024-34664LOW2.4Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypas...
CVE-2024-34663MEDIUM5.5Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory...
CVE-2024-34662HIGH7.8Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Rel...
CVE-2024-9292MEDIUM6.4The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions...
CVE-2024-9021MEDIUM5.4In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to i...
CVE-2024-8983MEDIUM4.8Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-21533MEDIUM6.5All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif...
CVE-2024-21532HIGH7.3All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user in...
CVE-2024-9026LOW3.3In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configu...
CVE-2024-8927HIGH7.5In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to ...
CVE-2024-8926HIGH8.8In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configu...
CVE-2024-8925MEDIUM5.3In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data ...
CVE-2024-47594MEDIUM5.4SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip...
CVE-2024-45382MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.
CVE-2024-45282MEDIUM5.3Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified b...
CVE-2024-45278MEDIUM5.4SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vul...
CVE-2024-45277MEDIUM4.3The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability ...
CVE-2024-43697MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2024-43696MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now