2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47013HIGH7.8In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This c...
CVE-2024-47012HIGH7.8In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bound...
CVE-2024-44101HIGH7.5there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote d...
CVE-2024-44100HIGH7.5Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
CVE-2024-44098HIGH7.4In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free....
CVE-2024-9598HIGH8.8The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2024-45785HIGH7.5MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other use...
CVE-2024-9235HIGH8.8The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2024-47005HIGH8.1Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users on...
CVE-2024-45829HIGH7.5Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly...
CVE-2024-43424HIGH7.5Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. C...
CVE-2024-42420HIGH7.5Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword se...
CVE-2024-10011HIGH8.1The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 vi...
CVE-2024-10353HIGH7.2A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown f...
CVE-2024-10351HIGH8.8A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function s...
CVE-2024-49359HIGH7.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ...
CVE-2024-49357HIGH7.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ...
CVE-2024-7763HIGH7.5In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to o...
CVE-2024-48931HIGH7.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ...
CVE-2024-48423HIGH7.8An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function wi...
CVE-2024-48208HIGH8.6pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the...
CVE-2024-47881HIGH8.8OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3....
CVE-2024-47879HIGH8.8OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request f...
CVE-2024-45263HIGH8.8An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upl...
CVE-2024-45262HIGH8.8An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The par...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now