Skip to main content

Year archive

CVEs published in 2024

Archive summary

39,957 CVEs published in 2024 — 3,705 Critical, 13,537 High, 21,359 Medium, 1,341 Low, 15 Unrated.

CVE-2023-52322

Published Jan 4, 2024

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29962

Published Jan 4, 2024

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6738

Published Jan 4, 2024

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6733

Published Jan 4, 2024

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. Th…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6498

Published Jan 4, 2024

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insu…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0225

Published Jan 4, 2024

Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security seve…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0224

Published Jan 4, 2024

Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security se…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0223

Published Jan 4, 2024

Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-0222

Published Jan 4, 2024

Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a cr…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-20809

Published Jan 4, 2024

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20808

Published Jan 4, 2024

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20807

Published Jan 4, 2024

Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-20806

Published Jan 4, 2024

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20805

Published Jan 4, 2024

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-20804

Published Jan 4, 2024

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attacke…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20803

Published Jan 4, 2024

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20802

Published Jan 4, 2024

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21634

Published Jan 3, 2024

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-50256

Published Jan 3, 2024

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6540

Published Jan 3, 2024

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosur…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6338

Published Jan 3, 2024

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated pri…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49442

Published Jan 3, 2024

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 39,726-39,750 of 39,957 CVEsPage 1590 of 1599