2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0224 | HIGH | 8.8 | 1.0% | Jan 4, 2024 | Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-0223 | HIGH | 8.8 | 10.1% | Jan 4, 2024 | Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit ... |
| CVE-2024-0222 | HIGH | 8.8 | 1.1% | Jan 4, 2024 | Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the rende... |
| CVE-2024-20809 | MEDIUM | 5.5 | 0.1% | Jan 4, 2024 | Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access ... |
| CVE-2024-20808 | MEDIUM | 5.5 | 0.1% | Jan 4, 2024 | Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access ... |
| CVE-2024-20807 | LOW | 3.3 | 0.2% | Jan 4, 2024 | Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensiti... |
| CVE-2024-20806 | MEDIUM | 5.5 | 0.1% | Jan 4, 2024 | Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notifica... |
| CVE-2024-20805 | MEDIUM | 5.5 | 0.2% | Jan 4, 2024 | Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, a... |
| CVE-2024-20804 | MEDIUM | 5.5 | 0.2% | Jan 4, 2024 | Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12... |
| CVE-2024-20803 | MEDIUM | 6.5 | 0.3% | Jan 4, 2024 | Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attacke... |
| CVE-2024-20802 | MEDIUM | 5.5 | 0.2% | Jan 4, 2024 | Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users&... |
| CVE-2024-21634 | HIGH | 7.5 | 0.8% | Jan 3, 2024 | Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service iss... |
| CVE-2024-21633 | HIGH | 7.8 | 1.3% | Jan 3, 2024 | Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files'... |
| CVE-2024-21631 | MEDIUM | 6.5 | 0.6% | Jan 3, 2024 | Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16... |
| CVE-2024-21622 | HIGH | 8.8 | 0.6% | Jan 3, 2024 | Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerabi... |
| CVE-2024-0217 | LOW | 3.3 | 0.2% | Jan 3, 2024 | A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction cou... |
| CVE-2024-21911 | MEDIUM | 6.1 | 1.2% | Jan 3, 2024 | TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote... |
| CVE-2024-21910 | MEDIUM | 6.1 | 1.0% | Jan 3, 2024 | TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attack... |
| CVE-2024-21909 | HIGH | 7.5 | 1.1% | Jan 3, 2024 | PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger t... |
| CVE-2024-21908 | MEDIUM | 6.1 | 1.1% | Jan 3, 2024 | TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote... |
| CVE-2024-21907 | HIGH | 7.5 | 32.9% | Jan 3, 2024 | Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data... |
| CVE-2024-0201 | MEDIUM | 4.3 | 0.4% | Jan 3, 2024 | The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2024-0211 | HIGH | 7.5 | 0.5% | Jan 3, 2024 | DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file |
| CVE-2024-0210 | HIGH | 7.5 | 0.5% | Jan 3, 2024 | Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file |
| CVE-2024-0209 | HIGH | 7.5 | 0.6% | Jan 3, 2024 | IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now