2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1444 | — | — | — | Feb 16, 2024 | Rejected reason: Erroneous assignment |
| CVE-2024-1342 | — | — | — | Feb 16, 2024 | Rejected reason: Unable to reproduce. |
| CVE-2024-25320 | CRITICAL | 9.8 | 0.7% | Feb 16, 2024 | Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /af... |
| CVE-2024-21775 | HIGH | 8.8 | 5.0% | Feb 16, 2024 | Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in re... |
| CVE-2024-22426 | CRITICAL | 9.8 | 1.4% | Feb 16, 2024 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated... |
| CVE-2024-22425 | CRITICAL | 9.8 | 0.5% | Feb 16, 2024 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthe... |
| CVE-2024-25466 | HIGH | 7.8 | 0.5% | Feb 16, 2024 | Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local att... |
| CVE-2024-24377 | CRITICAL | 9.8 | 1.1% | Feb 16, 2024 | An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information ... |
| CVE-2024-22854 | MEDIUM | 6.1 | 0.4% | Feb 16, 2024 | DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61... |
| CVE-2024-25415 | HIGH | 7.2 | 27.2% | Feb 16, 2024 | A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to ex... |
| CVE-2024-25414 | CRITICAL | 9.8 | 1.6% | Feb 16, 2024 | An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code vi... |
| CVE-2024-25413 | HIGH | 7.2 | 1.5% | Feb 16, 2024 | A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 all... |
| CVE-2024-0041 | HIGH | 7 | 0.1% | Feb 16, 2024 | In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error... |
| CVE-2024-0040 | HIGH | 7.5 | 2.0% | Feb 16, 2024 | In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead ... |
| CVE-2024-0038 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injectio... |
| CVE-2024-0037 | LOW | 3.3 | 0.1% | Feb 16, 2024 | In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a ... |
| CVE-2024-0036 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on s... |
| CVE-2024-0035 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to ... |
| CVE-2024-0034 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BA... |
| CVE-2024-0033 | HIGH | 7.8 | 0.2% | Feb 16, 2024 | In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead... |
| CVE-2024-0032 | MEDIUM | 6.5 | 0.5% | Feb 16, 2024 | In multiple locations, there is a possible way to request access to directories that should be hidden due to improper in... |
| CVE-2024-0031 | CRITICAL | 9.8 | 0.6% | Feb 16, 2024 | In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input ... |
| CVE-2024-0030 | MEDIUM | 5.5 | 0.4% | Feb 16, 2024 | In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. T... |
| CVE-2024-0029 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic ... |
| CVE-2024-0014 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now