2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47033HIGH7.8In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could le...
CVE-2024-47031HIGH7.4Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.
CVE-2024-47027HIGH7.8In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to imprope...
CVE-2024-47024HIGH7.8In vring_size of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to an intege...
CVE-2024-47023HIGH8.1there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of p...
CVE-2024-47022HIGH7.5Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.
CVE-2024-47021HIGH7.5In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. T...
CVE-2024-47020HIGH7.5Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.
CVE-2024-47017HIGH7.8In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead t...
CVE-2024-47016HIGH7.8there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privil...
CVE-2024-47014HIGH8.8Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.
CVE-2024-47013HIGH7.8In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This c...
CVE-2024-47012HIGH7.8In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bound...
CVE-2024-44101HIGH7.5there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote d...
CVE-2024-44100HIGH7.5Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
CVE-2024-44098HIGH7.4In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free....
CVE-2024-9598HIGH8.8The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2024-45785HIGH7.5MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other use...
CVE-2024-9235HIGH8.8The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2024-47005HIGH8.1Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users on...
CVE-2024-45829HIGH7.5Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly...
CVE-2024-43424HIGH7.5Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. C...
CVE-2024-42420HIGH7.5Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword se...
CVE-2024-10011HIGH8.1The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 vi...
CVE-2024-10353HIGH7.2A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown f...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now