2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1444Rejected reason: Erroneous assignment
CVE-2024-1342Rejected reason: Unable to reproduce.
CVE-2024-25320CRITICAL9.8Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /af...
CVE-2024-21775HIGH8.8Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in re...
CVE-2024-22426CRITICAL9.8Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated...
CVE-2024-22425CRITICAL9.8Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthe...
CVE-2024-25466HIGH7.8Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local att...
CVE-2024-24377CRITICAL9.8An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information ...
CVE-2024-22854MEDIUM6.1DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61...
CVE-2024-25415HIGH7.2A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to ex...
CVE-2024-25414CRITICAL9.8An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code vi...
CVE-2024-25413HIGH7.2A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 all...
CVE-2024-0041HIGH7In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error...
CVE-2024-0040HIGH7.5In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead ...
CVE-2024-0038HIGH7.8In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injectio...
CVE-2024-0037LOW3.3In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a ...
CVE-2024-0036HIGH7.8In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on s...
CVE-2024-0035HIGH7.8In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to ...
CVE-2024-0034HIGH7.8In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BA...
CVE-2024-0033HIGH7.8In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead...
CVE-2024-0032MEDIUM6.5In multiple locations, there is a possible way to request access to directories that should be hidden due to improper in...
CVE-2024-0031CRITICAL9.8In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input ...
CVE-2024-0030MEDIUM5.5In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. T...
CVE-2024-0029HIGH7.8In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic ...
CVE-2024-0014HIGH7.8In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now