2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9524HIGH7.8Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime V...
CVE-2024-13962HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 2...
CVE-2024-13961HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 o...
CVE-2024-13960HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Wi...
CVE-2024-13959HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows...
CVE-2024-13944HIGH7.8Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2....
CVE-2024-13759HIGH7.8Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attack...
CVE-2024-9448HIGH7.5On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged...
CVE-2024-8100HIGH8.7On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used ...
CVE-2024-13009HIGH7.2In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when in...
CVE-2024-6648HIGH7.5Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote u...
CVE-2024-13793HIGH7.3The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execut...
CVE-2024-47619HIGH7.5syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo....
CVE-2024-49847HIGH7.5Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
CVE-2024-49845HIGH7.8Memory corruption during the FRS UDS generation process.
CVE-2024-49844HIGH7.8Memory corruption while triggering commands in the PlayReady Trusted application.
CVE-2024-49842HIGH7.8Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
CVE-2024-49841HIGH7.8Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
CVE-2024-49835HIGH7.8Memory corruption while reading secure file.
CVE-2024-49830HIGH7.8Memory corruption while processing an IOCTL call to set mixer controls.
CVE-2024-49829HIGH7.8Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
CVE-2024-45583HIGH7.8Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.
CVE-2024-45581HIGH7.8Memory corruption while sound model registration for voice activation with audio kernel driver.
CVE-2024-45579HIGH7.8Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request informa...
CVE-2024-45578HIGH7.8Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now