2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-21832LOW3.5A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON re...
CVE-2024-6501LOW3.1A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 c...
CVE-2024-28067LOW3.7A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode o...
CVE-2024-37253LOW2.7Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi...
CVE-2024-35777LOW3.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto...
CVE-2024-38372LOW2Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(...
CVE-2024-37234LOW3.5URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad...
CVE-2024-40594LOW2.3The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l...
CVE-2024-32754LOW3.1Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i...
CVE-2024-29508LOW3.3Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in th...
CVE-2024-6126LOW3.2A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pa...
CVE-2024-6470LOW2.7A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2024-39353LOW2.7Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them ...
CVE-2024-39324LOW3.8aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2...
CVE-2024-34600LOW3.3Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows loc...
CVE-2024-34599LOW3.3Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Ti...
CVE-2024-34597LOW3.3Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary docume...
CVE-2024-34586LOW3.3Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure ...
CVE-2024-34583LOW3.3Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifi...
CVE-2024-20900LOW3.3Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode with...
CVE-2024-36278LOW3.3in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2024-31071LOW3.3in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2024-36995LOW3.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-39846LOW3.5NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz...
CVE-2024-39307LOW3.5Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now