2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20911 | LOW | 2.6 | 0.3% | Feb 17, 2024 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a... |
| CVE-2024-20909 | HIGH | 7.5 | 0.4% | Feb 17, 2024 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a... |
| CVE-2024-20907 | MEDIUM | 6.1 | 0.3% | Feb 17, 2024 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File down... |
| CVE-2024-20905 | LOW | 2.7 | 0.5% | Feb 17, 2024 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S... |
| CVE-2024-20903 | MEDIUM | 6.5 | 0.4% | Feb 17, 2024 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.21 a... |
| CVE-2024-21984 | MEDIUM | 6.9 | 0.3% | Feb 16, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected ... |
| CVE-2024-21983 | MEDIUM | 6.5 | 0.5% | Feb 16, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnera... |
| CVE-2024-24758 | MEDIUM | 4.5 | 0.8% | Feb 16, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-or... |
| CVE-2024-24750 | MEDIUM | 6.5 | 0.7% | Feb 16, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consum... |
| CVE-2024-25628 | HIGH | 7.6 | 0.4% | Feb 16, 2024 | Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access t... |
| CVE-2024-25627 | MEDIUM | 4.8 | 0.4% | Feb 16, 2024 | Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able ... |
| CVE-2024-25083 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiat... |
| CVE-2024-21987 | MEDIUM | 5.4 | 0.3% | Feb 16, 2024 | SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter S... |
| CVE-2024-0023 | HIGH | 7.8 | 0.4% | Feb 16, 2024 | In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds ch... |
| CVE-2024-0021 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to en... |
| CVE-2024-0020 | MEDIUM | 5.5 | 0.1% | Feb 16, 2024 | In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a diff... |
| CVE-2024-0019 | MEDIUM | 5 | 0.1% | Feb 16, 2024 | In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when rest... |
| CVE-2024-0018 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overf... |
| CVE-2024-0017 | MEDIUM | 5.5 | 0.1% | Feb 16, 2024 | In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This c... |
| CVE-2024-0016 | MEDIUM | 5.3 | 0.2% | Feb 16, 2024 | In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired d... |
| CVE-2024-21915 | HIGH | 8.8 | 1.0% | Feb 16, 2024 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, ... |
| CVE-2024-1591 | LOW | 3.3 | 0.2% | Feb 16, 2024 | Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configure... |
| CVE-2024-0015 | HIGH | 7.8 | 0.4% | Feb 16, 2024 | In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to ... |
| CVE-2024-1515 | — | — | — | Feb 16, 2024 | Rejected reason: Erroneous assignement |
| CVE-2024-23591 | LOW | 2.3 | 0.2% | Feb 16, 2024 | ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now