2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20911LOW2.6Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a...
CVE-2024-20909HIGH7.5Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a...
CVE-2024-20907MEDIUM6.1Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File down...
CVE-2024-20905LOW2.7Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S...
CVE-2024-20903MEDIUM6.5Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.21 a...
CVE-2024-21984MEDIUM6.9StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected ...
CVE-2024-21983MEDIUM6.5StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnera...
CVE-2024-24758MEDIUM4.5Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-or...
CVE-2024-24750MEDIUM6.5Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consum...
CVE-2024-25628HIGH7.6Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access t...
CVE-2024-25627MEDIUM4.8Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able ...
CVE-2024-25083HIGH7.8An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiat...
CVE-2024-21987MEDIUM5.4SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter S...
CVE-2024-0023HIGH7.8In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds ch...
CVE-2024-0021HIGH7.8In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to en...
CVE-2024-0020MEDIUM5.5In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a diff...
CVE-2024-0019MEDIUM5In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when rest...
CVE-2024-0018HIGH7.8In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overf...
CVE-2024-0017MEDIUM5.5In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This c...
CVE-2024-0016MEDIUM5.3In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired d...
CVE-2024-21915HIGH8.8 A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, ...
CVE-2024-1591LOW3.3Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configure...
CVE-2024-0015HIGH7.8In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to ...
CVE-2024-1515Rejected reason: Erroneous assignement
CVE-2024-23591LOW2.3ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now