2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-24938MEDIUM5.3In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
CVE-2024-24937MEDIUM5.4In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
CVE-2024-24936MEDIUM5.3In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
CVE-2024-0684MEDIUM5.5A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred byt...
CVE-2024-22365MEDIUM5.5linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo ...
CVE-2024-24808MEDIUM6.1pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorre...
CVE-2024-20828MEDIUM4.6Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to...
CVE-2024-20827MEDIUM4.6Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access ...
CVE-2024-20826MEDIUM5.5Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sens...
CVE-2024-20825MEDIUM5.5Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to acces...
CVE-2024-20824MEDIUM5.5Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers ...
CVE-2024-20823MEDIUM5.5Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attacke...
CVE-2024-20822MEDIUM5.5Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attack...
CVE-2024-20816MEDIUM6.5Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 al...
CVE-2024-20815MEDIUM6.5Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 all...
CVE-2024-20814MEDIUM5.5Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers acce...
CVE-2024-1210MEDIUM5.3The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1209MEDIUM5.3The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1208MEDIUM5.3The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1177MEDIUM5.3The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-1121MEDIUM5.3The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-1092MEDIUM4.3The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2024-1075MEDIUM5.3The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information...
CVE-2024-1046MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2024-0969MEDIUM5.3The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now