2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-36354HIGH7.5Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r...
CVE-2024-36352HIGH8.4Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote...
CVE-2024-36342HIGH8.8Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in ...
CVE-2024-36326HIGH8.4Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a...
CVE-2024-21947HIGH7.5Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary m...
CVE-2024-49714HIGH7.8In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea...
CVE-2024-56190HIGH7.8In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T...
CVE-2024-13068HIGH7.3Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: fro...
CVE-2024-43115HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s...
CVE-2024-49730HIGH7.8In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation...
CVE-2024-49720HIGH7.8In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi...
CVE-2024-40653HIGH7.3In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba...
CVE-2024-58259HIGH8.2A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert...
CVE-2024-52284HIGH7.7Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou...
CVE-2024-12925HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. ...
CVE-2024-32589HIGH7.1Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ...
CVE-2024-46917HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur...
CVE-2024-46916HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys...
CVE-2024-13986HIGH8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an...
CVE-2024-58240HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ...
CVE-2024-13807HIGH7.5The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-13982HIGH8.7SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar...
CVE-2024-37777HIGH8.8O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
CVE-2024-47853HIGH8.8An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w...
CVE-2024-48988HIGH7.6SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now