2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36354 | HIGH | 7.5 | 0.2% | Sep 6, 2025 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r... |
| CVE-2024-36352 | HIGH | 8.4 | 0.1% | Sep 6, 2025 | Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote... |
| CVE-2024-36342 | HIGH | 8.8 | 0.2% | Sep 6, 2025 | Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in ... |
| CVE-2024-36326 | HIGH | 8.4 | 0.1% | Sep 6, 2025 | Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a... |
| CVE-2024-21947 | HIGH | 7.5 | 0.1% | Sep 6, 2025 | Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary m... |
| CVE-2024-49714 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea... |
| CVE-2024-56190 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T... |
| CVE-2024-13068 | HIGH | 7.3 | 0.1% | Sep 3, 2025 | Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: fro... |
| CVE-2024-43115 | HIGH | 8.8 | 0.5% | Sep 3, 2025 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s... |
| CVE-2024-49730 | HIGH | 7.8 | 0.1% | Sep 2, 2025 | In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation... |
| CVE-2024-49720 | HIGH | 7.8 | 0.1% | Sep 2, 2025 | In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi... |
| CVE-2024-40653 | HIGH | 7.3 | 0.1% | Sep 2, 2025 | In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba... |
| CVE-2024-58259 | HIGH | 8.2 | 0.5% | Sep 2, 2025 | A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert... |
| CVE-2024-52284 | HIGH | 7.7 | 0.2% | Sep 2, 2025 | Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou... |
| CVE-2024-12925 | HIGH | 7.3 | 0.1% | Sep 1, 2025 | Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. ... |
| CVE-2024-32589 | HIGH | 7.1 | 0.2% | Aug 31, 2025 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ... |
| CVE-2024-46917 | HIGH | 8.1 | 0.2% | Aug 29, 2025 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur... |
| CVE-2024-46916 | HIGH | 8.1 | 0.3% | Aug 29, 2025 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys... |
| CVE-2024-13986 | HIGH | 8.8 | 1.7% | Aug 28, 2025 | Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an... |
| CVE-2024-58240 | HIGH | 7.8 | 0.3% | Aug 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ... |
| CVE-2024-13807 | HIGH | 7.5 | 0.4% | Aug 28, 2025 | The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-13982 | HIGH | 8.7 | 1.0% | Aug 27, 2025 | SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar... |
| CVE-2024-37777 | HIGH | 8.8 | 0.5% | Aug 27, 2025 | O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function. |
| CVE-2024-47853 | HIGH | 8.8 | 0.3% | Aug 26, 2025 | An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w... |
| CVE-2024-48988 | HIGH | 7.6 | 0.6% | Aug 22, 2025 | SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now