2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53022 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption may occur during communication between primary and guest VM. |
| CVE-2024-53014 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption may occur while validating ports and channels in Audio driver. |
| CVE-2024-53012 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption may occur due to improper input validation in clock device. |
| CVE-2024-53011 | HIGH | 7.9 | 0.1% | Mar 3, 2025 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. |
| CVE-2024-49836 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption may occur during the synchronization of the camera`s frame processing pipeline. |
| CVE-2024-45580 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. |
| CVE-2024-43062 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization. |
| CVE-2024-43061 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound mode... |
| CVE-2024-43060 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. |
| CVE-2024-43059 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. |
| CVE-2024-43057 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while processing command in Glink linux. |
| CVE-2024-43056 | MEDIUM | 6.5 | 0.1% | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
| CVE-2024-43055 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while processing camera use case IOCTL call. |
| CVE-2024-43051 | MEDIUM | 5.5 | 0.1% | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-38426 | MEDIUM | 5.3 | 0.2% | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| CVE-2024-24778 | MEDIUM | 6.5 | 0.6% | Mar 3, 2025 | Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou... |
| CVE-2024-10925 | MEDIUM | 5.3 | 0.3% | Mar 3, 2025 | A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1... |
| CVE-2024-8186 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.... |
| CVE-2024-53386 | MEDIUM | 6.1 | 0.2% | Mar 3, 2025 | Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di... |
| CVE-2024-53382 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ... |
| CVE-2024-36353 | MEDIUM | 6.5 | 0.1% | Mar 2, 2025 | Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem... |
| CVE-2024-55907 | MEDIUM | 5.3 | 0.2% | Mar 2, 2025 | IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno... |
| CVE-2024-41778 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi... |
| CVE-2024-13833 | HIGH | 7.2 | 0.6% | Mar 1, 2025 | The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, ... |
| CVE-2024-13546 | MEDIUM | 4.3 | 0.3% | Mar 1, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now