2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24938 | MEDIUM | 5.3 | 0.7% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation |
| CVE-2024-24937 | MEDIUM | 5.4 | 0.4% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible |
| CVE-2024-24936 | MEDIUM | 5.3 | 0.3% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed |
| CVE-2024-0684 | MEDIUM | 5.5 | 0.5% | Feb 6, 2024 | A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred byt... |
| CVE-2024-22365 | MEDIUM | 5.5 | 0.5% | Feb 6, 2024 | linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo ... |
| CVE-2024-24808 | MEDIUM | 6.1 | 0.5% | Feb 6, 2024 | pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorre... |
| CVE-2024-20828 | MEDIUM | 4.6 | 0.2% | Feb 6, 2024 | Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to... |
| CVE-2024-20827 | MEDIUM | 4.6 | 0.2% | Feb 6, 2024 | Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access ... |
| CVE-2024-20826 | MEDIUM | 5.5 | 0.1% | Feb 6, 2024 | Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sens... |
| CVE-2024-20825 | MEDIUM | 5.5 | 0.2% | Feb 6, 2024 | Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to acces... |
| CVE-2024-20824 | MEDIUM | 5.5 | 0.2% | Feb 6, 2024 | Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers ... |
| CVE-2024-20823 | MEDIUM | 5.5 | 0.2% | Feb 6, 2024 | Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attacke... |
| CVE-2024-20822 | MEDIUM | 5.5 | 0.2% | Feb 6, 2024 | Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attack... |
| CVE-2024-20816 | MEDIUM | 6.5 | 0.4% | Feb 6, 2024 | Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 al... |
| CVE-2024-20815 | MEDIUM | 6.5 | 0.4% | Feb 6, 2024 | Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 all... |
| CVE-2024-20814 | MEDIUM | 5.5 | 0.2% | Feb 6, 2024 | Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers acce... |
| CVE-2024-1210 | MEDIUM | 5.3 | 2.0% | Feb 5, 2024 | The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-1209 | MEDIUM | 5.3 | 2.4% | Feb 5, 2024 | The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-1208 | MEDIUM | 5.3 | 5.3% | Feb 5, 2024 | The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-1177 | MEDIUM | 5.3 | 0.5% | Feb 5, 2024 | The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2024-1121 | MEDIUM | 5.3 | 0.6% | Feb 5, 2024 | The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2024-1092 | MEDIUM | 4.3 | 0.4% | Feb 5, 2024 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2024-1075 | MEDIUM | 5.3 | 0.7% | Feb 5, 2024 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information... |
| CVE-2024-1046 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2024-0969 | MEDIUM | 5.3 | 0.5% | Feb 5, 2024 | The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now