2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53022HIGH7.8Memory corruption may occur during communication between primary and guest VM.
CVE-2024-53014HIGH7.8Memory corruption may occur while validating ports and channels in Audio driver.
CVE-2024-53012HIGH7.8Memory corruption may occur due to improper input validation in clock device.
CVE-2024-53011HIGH7.9Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
CVE-2024-49836HIGH7.8Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
CVE-2024-45580HIGH7.8Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
CVE-2024-43062HIGH7.8Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
CVE-2024-43061HIGH7.8Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound mode...
CVE-2024-43060HIGH7.8Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
CVE-2024-43059HIGH7.8Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
CVE-2024-43057HIGH7.8Memory corruption while processing command in Glink linux.
CVE-2024-43056MEDIUM6.5Transient DOS during hypervisor virtual I/O operation in a virtual machine.
CVE-2024-43055HIGH7.8Memory corruption while processing camera use case IOCTL call.
CVE-2024-43051MEDIUM5.5Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-38426MEDIUM5.3While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-24778MEDIUM6.5Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou...
CVE-2024-10925MEDIUM5.3A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1...
CVE-2024-8186MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17....
CVE-2024-53386MEDIUM6.1Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di...
CVE-2024-53382MEDIUM5.4Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ...
CVE-2024-36353MEDIUM6.5Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem...
CVE-2024-55907MEDIUM5.3IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno...
CVE-2024-41778MEDIUM6.5IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi...
CVE-2024-13833HIGH7.2The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, ...
CVE-2024-13546MEDIUM4.3The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now