2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0224HIGH8.8Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit hea...
CVE-2024-0223HIGH8.8Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit ...
CVE-2024-0222HIGH8.8Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the rende...
CVE-2024-20809MEDIUM5.5Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access ...
CVE-2024-20808MEDIUM5.5Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access ...
CVE-2024-20807LOW3.3Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensiti...
CVE-2024-20806MEDIUM5.5Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notifica...
CVE-2024-20805MEDIUM5.5Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, a...
CVE-2024-20804MEDIUM5.5Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12...
CVE-2024-20803MEDIUM6.5Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attacke...
CVE-2024-20802MEDIUM5.5Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users&...
CVE-2024-21634HIGH7.5Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service iss...
CVE-2024-21633HIGH7.8Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files'...
CVE-2024-21631MEDIUM6.5Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16...
CVE-2024-21622HIGH8.8Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerabi...
CVE-2024-0217LOW3.3A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction cou...
CVE-2024-21911MEDIUM6.1TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote...
CVE-2024-21910MEDIUM6.1TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attack...
CVE-2024-21909HIGH7.5PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger t...
CVE-2024-21908MEDIUM6.1TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote...
CVE-2024-21907HIGH7.5Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data...
CVE-2024-0201MEDIUM4.3The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2024-0211HIGH7.5DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
CVE-2024-0210HIGH7.5Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
CVE-2024-0209HIGH7.5IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now