2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25984MEDIUM6.2In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could...
CVE-2024-22010MEDIUM5.5In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to...
CVE-2024-22007MEDIUM6.2In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to l...
CVE-2024-22006MEDIUM5.3OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
CVE-2024-26618MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with exist...
CVE-2024-26615MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/smc: fix illegal rmb_desc access in SMC-D conne...
CVE-2024-26612MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfs, fscache: Prevent Oops in fscache_put_cache()...
CVE-2024-26611MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of multi-buffer BPF helpers for ZC X...
CVE-2024-1487MEDIUM5.4The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which ...
CVE-2024-1290MEDIUM6.5The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from render...
CVE-2024-1279MEDIUM4.3The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from le...
CVE-2024-1273MEDIUM6.1The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a r...
CVE-2024-0561MEDIUM5.4The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before o...
CVE-2024-0559MEDIUM6.5The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before ou...
CVE-2024-0047MEDIUM5.5In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in ...
CVE-2024-0045MEDIUM6.5In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could l...
CVE-2024-0044MEDIUM6.7In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input valid...
CVE-2024-1441MEDIUM5.5An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces...
CVE-2024-28823MEDIUM6.1Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.ht...
CVE-2024-2365MEDIUM4.2A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is ...
CVE-2024-2364MEDIUM4.6A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown functi...
CVE-2024-2363MEDIUM5.3** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. ...
CVE-2024-2354MEDIUM6.5A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of...
CVE-2024-1870MEDIUM4.3The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-28089MEDIUM5.2Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now