2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57514 | MEDIUM | 4.8 | 0.9% | Jan 28, 2025 | The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi... |
| CVE-2024-57376 | HIGH | 8.8 | 3.6% | Jan 28, 2025 | Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C... |
| CVE-2024-55968 | HIGH | 8.8 | 1.0% | Jan 28, 2025 | An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handli... |
| CVE-2024-29869 | MEDIUM | 5.5 | 0.3% | Jan 28, 2025 | Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the fil... |
| CVE-2024-40677 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections... |
| CVE-2024-40676 | HIGH | 7.7 | 0.2% | Jan 28, 2025 | In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an ... |
| CVE-2024-40675 | HIGH | 7.5 | 0.3% | Jan 28, 2025 | In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead ... |
| CVE-2024-40674 | MEDIUM | 5.3 | 0.2% | Jan 28, 2025 | In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a ... |
| CVE-2024-40673 | MEDIUM | 6.5 | 0.3% | Jan 28, 2025 | In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod... |
| CVE-2024-40672 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permis... |
| CVE-2024-40670 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil... |
| CVE-2024-40669 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil... |
| CVE-2024-40651 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ... |
| CVE-2024-40649 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ... |
| CVE-2024-34748 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi... |
| CVE-2024-34733 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. Th... |
| CVE-2024-34732 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could l... |
| CVE-2024-13484 | HIGH | 8.2 | 0.2% | Jan 28, 2025 | A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all nam... |
| CVE-2024-8401 | MEDIUM | 5.4 | 0.3% | Jan 28, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a... |
| CVE-2024-7881 | MEDIUM | 5.1 | 0.2% | Jan 28, 2025 | An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged locati... |
| CVE-2024-6351 | MEDIUM | 4.3 | 0.2% | Jan 28, 2025 | A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert |
| CVE-2024-11956 | HIGH | 7.2 | 0.8% | Jan 28, 2025 | A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affect... |
| CVE-2024-11954 | MEDIUM | 4.8 | 1.0% | Jan 28, 2025 | A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func... |
| CVE-2024-23953 | MEDIUM | 6.5 | 1.1% | Jan 28, 2025 | Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid s... |
| CVE-2024-13527 | MEDIUM | 5.4 | 0.2% | Jan 28, 2025 | The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now