2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21799 | HIGH | 7.1 | 0.7% | Nov 13, 2024 | Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user ... |
| CVE-2024-43093 | HIGH | 7.3 | 0.7% | Nov 13, 2024 | In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prev... |
| CVE-2024-43089 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission ... |
| CVE-2024-43088 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to an... |
| CVE-2024-43087 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled access... |
| CVE-2024-43085 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocki... |
| CVE-2024-43081 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo... |
| CVE-2024-43080 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization.... |
| CVE-2024-40671 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a mi... |
| CVE-2024-40661 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due... |
| CVE-2024-40660 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a lo... |
| CVE-2024-34747 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This c... |
| CVE-2024-34729 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to... |
| CVE-2024-34719 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca... |
| CVE-2024-31337 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This... |
| CVE-2024-23715 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lea... |
| CVE-2024-9413 | HIGH | 8 | 0.4% | Nov 13, 2024 | The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, p... |
| CVE-2024-52291 | HIGH | 7.2 | 1.1% | Nov 13, 2024 | Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system v... |
| CVE-2024-51996 | HIGH | 7.5 | 0.6% | Nov 13, 2024 | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p... |
| CVE-2024-52299 | HIGH | 7.5 | 0.5% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService... |
| CVE-2024-52298 | HIGH | 7.5 | 0.7% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view an... |
| CVE-2024-52293 | HIGH | 7.2 | 1.3% | Nov 13, 2024 | Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function Fi... |
| CVE-2024-50972 | HIGH | 7.2 | 0.7% | Nov 13, 2024 | A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attacker... |
| CVE-2024-50971 | HIGH | 7.2 | 0.7% | Nov 13, 2024 | A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to... |
| CVE-2024-50970 | HIGH | 8.8 | 0.5% | Nov 13, 2024 | A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now