2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1929 | HIGH | 8.4 | 0.3% | May 8, 2024 | Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Co... |
| CVE-2024-4456 | MEDIUM | 5.4 | 0.3% | May 8, 2024 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payloa... |
| CVE-2024-23551 | MEDIUM | 6.5 | 0.2% | May 7, 2024 | Database scanning using username and password stores the credentials in plaintext or encoded format within files at the ... |
| CVE-2024-4030 | HIGH | 7.1 | 0.3% | May 7, 2024 | On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writ... |
| CVE-2024-34346 | CRITICAL | 9 | 0.4% | May 7, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly wea... |
| CVE-2024-27273 | HIGH | 7.8 | 0.1% | May 7, 2024 | IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose app... |
| CVE-2024-23713 | HIGH | 7.8 | 0.1% | May 7, 2024 | In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications se... |
| CVE-2024-23712 | MEDIUM | 5.5 | 0.1% | May 7, 2024 | In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_acce... |
| CVE-2024-23710 | HIGH | 7.8 | 0.1% | May 7, 2024 | In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary ap... |
| CVE-2024-23709 | MEDIUM | 6.5 | 0.8% | May 7, 2024 | In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote ... |
| CVE-2024-23708 | HIGH | 7.8 | 0.3% | May 7, 2024 | In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a cli... |
| CVE-2024-23707 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local... |
| CVE-2024-23706 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This c... |
| CVE-2024-23705 | HIGH | 7.8 | 0.3% | May 7, 2024 | In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validat... |
| CVE-2024-23704 | HIGH | 7.8 | 0.1% | May 7, 2024 | In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due t... |
| CVE-2024-0043 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a lo... |
| CVE-2024-0042 | HIGH | 7.8 | 0.1% | May 7, 2024 | In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead ... |
| CVE-2024-0027 | MEDIUM | 5.5 | 0.1% | May 7, 2024 | In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. Thi... |
| CVE-2024-0026 | MEDIUM | 5.5 | 0.1% | May 7, 2024 | In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion.... |
| CVE-2024-0025 | HIGH | 7.8 | 0.1% | May 7, 2024 | In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error.... |
| CVE-2024-0024 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due ... |
| CVE-2024-0022 | MEDIUM | 5.5 | 0.1% | May 7, 2024 | In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationAc... |
| CVE-2024-4559 | MEDIUM | 6.5 | 1.0% | May 7, 2024 | Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially explo... |
| CVE-2024-4558 | CRITICAL | 9.6 | 1.3% | May 7, 2024 | Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-34315 | HIGH | 7.5 | 0.7% | May 7, 2024 | CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now