2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21799HIGH7.1Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user ...
CVE-2024-43093HIGH7.3In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prev...
CVE-2024-43089HIGH7.8In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission ...
CVE-2024-43088HIGH7.8In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to an...
CVE-2024-43087HIGH7.8In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled access...
CVE-2024-43085HIGH7.8In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocki...
CVE-2024-43081HIGH7.8In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo...
CVE-2024-43080HIGH7.8In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization....
CVE-2024-40671HIGH7.8In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a mi...
CVE-2024-40661HIGH7.8In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due...
CVE-2024-40660HIGH7.8In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a lo...
CVE-2024-34747HIGH7.8In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This c...
CVE-2024-34729HIGH7.8In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to...
CVE-2024-34719HIGH7.8In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca...
CVE-2024-31337HIGH7.8In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This...
CVE-2024-23715HIGH7.8In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lea...
CVE-2024-9413HIGH8The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, p...
CVE-2024-52291HIGH7.2Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system v...
CVE-2024-51996HIGH7.5Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p...
CVE-2024-52299HIGH7.5macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService...
CVE-2024-52298HIGH7.5macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view an...
CVE-2024-52293HIGH7.2Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function Fi...
CVE-2024-50972HIGH7.2A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attacker...
CVE-2024-50971HIGH7.2A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to...
CVE-2024-50970HIGH8.8A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now