2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57514MEDIUM4.8The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi...
CVE-2024-57376HIGH8.8Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C...
CVE-2024-55968HIGH8.8An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handli...
CVE-2024-29869MEDIUM5.5Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the fil...
CVE-2024-40677HIGH8.4In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections...
CVE-2024-40676HIGH7.7In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an ...
CVE-2024-40675HIGH7.5In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead ...
CVE-2024-40674MEDIUM5.3In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a ...
CVE-2024-40673MEDIUM6.5In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod...
CVE-2024-40672HIGH8.4In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permis...
CVE-2024-40670HIGH8.4In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2024-40669HIGH8.4In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2024-40651HIGH8.4In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ...
CVE-2024-40649HIGH8.4In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ...
CVE-2024-34748HIGH8.4In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi...
CVE-2024-34733HIGH8.4In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. Th...
CVE-2024-34732HIGH8.4In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could l...
CVE-2024-13484HIGH8.2A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all nam...
CVE-2024-8401MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a...
CVE-2024-7881MEDIUM5.1An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged locati...
CVE-2024-6351MEDIUM4.3A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert
CVE-2024-11956HIGH7.2A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affect...
CVE-2024-11954MEDIUM4.8A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func...
CVE-2024-23953MEDIUM6.5Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid s...
CVE-2024-13527MEDIUM5.4The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now