2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52452 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX L... |
| CVE-2024-12015 | HIGH | 7.7 | 0.5% | Dec 2, 2024 | The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' para... |
| CVE-2024-43053 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information. |
| CVE-2024-43052 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while processing API calls to NPU with invalid input. |
| CVE-2024-43050 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. |
| CVE-2024-43049 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver. |
| CVE-2024-43048 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption when invalid input is passed to invoke GPU Headroom API call. |
| CVE-2024-33063 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside w... |
| CVE-2024-33056 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-33044 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
| CVE-2024-33040 | HIGH | 7 | 0.1% | Dec 2, 2024 | Memory corruption while invoking redundant release command to release one buffer from user space as race condition can o... |
| CVE-2024-10490 | HIGH | 8.4 | 0.5% | Dec 2, 2024 | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required ... |
| CVE-2024-53104 | HIGH | 7.8 | 3.3% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS... |
| CVE-2024-53103 | HIGH | 7.8 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: hv_sock: Initializing vsk->trans to NULL to prevent... |
| CVE-2024-20138 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote inform... |
| CVE-2024-20137 | HIGH | 7.5 | 1.2% | Dec 2, 2024 | In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could ... |
| CVE-2024-20129 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of ... |
| CVE-2024-20128 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of ... |
| CVE-2024-20127 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of ... |
| CVE-2024-53605 | HIGH | 7.5 | 0.4% | Dec 2, 2024 | Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS... |
| CVE-2024-53750 | HIGH | 7.1 | 0.1% | Dec 1, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects Pa... |
| CVE-2024-53742 | HIGH | 7.1 | 0.2% | Dec 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems... |
| CVE-2024-45520 | HIGH | 7.5 | 0.5% | Dec 1, 2024 | WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption dur... |
| CVE-2024-53778 | HIGH | 7.1 | 0.2% | Nov 30, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows... |
| CVE-2024-53783 | HIGH | 7.6 | 0.5% | Nov 30, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzar Ahmed Ni Woo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now