2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1929HIGH8.4Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Co...
CVE-2024-4456MEDIUM5.4In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payloa...
CVE-2024-23551MEDIUM6.5Database scanning using username and password stores the credentials in plaintext or encoded format within files at the ...
CVE-2024-4030HIGH7.1On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writ...
CVE-2024-34346CRITICAL9Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly wea...
CVE-2024-27273HIGH7.8IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose app...
CVE-2024-23713HIGH7.8In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications se...
CVE-2024-23712MEDIUM5.5In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_acce...
CVE-2024-23710HIGH7.8In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary ap...
CVE-2024-23709MEDIUM6.5In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote ...
CVE-2024-23708HIGH7.8In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a cli...
CVE-2024-23707HIGH7.8In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local...
CVE-2024-23706HIGH7.8In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This c...
CVE-2024-23705HIGH7.8In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validat...
CVE-2024-23704HIGH7.8In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due t...
CVE-2024-0043HIGH7.8In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a lo...
CVE-2024-0042HIGH7.8In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead ...
CVE-2024-0027MEDIUM5.5In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. Thi...
CVE-2024-0026MEDIUM5.5In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion....
CVE-2024-0025HIGH7.8In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error....
CVE-2024-0024HIGH7.8In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due ...
CVE-2024-0022MEDIUM5.5In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationAc...
CVE-2024-4559MEDIUM6.5Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially explo...
CVE-2024-4558CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap c...
CVE-2024-34315HIGH7.5CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now