2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53021HIGH8.2Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020HIGH8.2Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53019HIGH8.2Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing so...
CVE-2024-53010HIGH7.8Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-57459HIGH7.3A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds ...
CVE-2024-54028HIGH7.8An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra...
CVE-2024-52035HIGH7.8An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. ...
CVE-2024-48877HIGH7.8A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers...
CVE-2024-57783HIGH8.1The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM outpu...
CVE-2024-12168HIGH7.8Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-11857HIGH8.5Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can creat...
CVE-2024-13917HIGH8.3An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-12224HIGH8.8Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create...
CVE-2024-54952HIGH7.5MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers ...
CVE-2024-49350HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12....
CVE-2024-51392HIGH8.8An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the ...
CVE-2024-22654HIGH7.5tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
CVE-2024-52588HIGH7.5Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks ...
CVE-2024-51453HIGH7.5IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. A...
CVE-2024-38341HIGH7.5IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than...
CVE-2024-13966HIGH7.3ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged ...
CVE-2024-49196HIGH7.5An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of...
CVE-2024-38866HIGH7.5Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
CVE-2024-9163HIGH7.5A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11....
CVE-2024-7803HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now