2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20830MEDIUM5.3Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock sett...
CVE-2024-20829MEDIUM5.3Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers t...
CVE-2024-22383MEDIUM6.2 Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Seri...
CVE-2024-21838MEDIUM5.4 Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Cent...
CVE-2024-21815MEDIUM6.5 Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are access...
CVE-2024-1782MEDIUM6.1The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' param...
CVE-2024-1769MEDIUM5.3The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14...
CVE-2024-1478MEDIUM5.3The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2024-1381MEDIUM6.5The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Info...
CVE-2024-1285MEDIUM6.5The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-1178MEDIUM5.3The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-1095MEDIUM5.3The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access...
CVE-2024-1093MEDIUM5.3The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2024-1088MEDIUM5.3The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2024-0698MEDIUM5.4The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointmen...
CVE-2024-1319MEDIUM4.3The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from lea...
CVE-2024-1316MEDIUM6.5The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does...
CVE-2024-27680MEDIUM6.1Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."
CVE-2024-27668MEDIUM6.1Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'
CVE-2024-27684MEDIUM6.1A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTA...
CVE-2024-21826MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storag...
CVE-2024-21816MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of ...
CVE-2024-20037MEDIUM6.7In pq, there is a possible write-what-where condition due to an incorrect bounds check. This could lead to local escalat...
CVE-2024-20036MEDIUM4.4In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclos...
CVE-2024-20033MEDIUM4.4In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now