2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46921MEDIUM6.5An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330,...
CVE-2024-46310CRITICAL9.1Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary ...
CVE-2024-44771MEDIUM6.1BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template functi...
CVE-2024-5743CRITICAL9.8An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve...
CVE-2024-46920MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le...
CVE-2024-46479HIGH8.8Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated a...
CVE-2024-6352MEDIUM4.3A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert
CVE-2024-57488MEDIUM6.5Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter ...
CVE-2024-57487MEDIUM6.5In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a...
CVE-2024-54999MEDIUM6.5MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General ...
CVE-2024-48883MEDIUM4.3An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108...
CVE-2024-46919MEDIUM5.3An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le...
CVE-2024-12211MEDIUM5.4Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
CVE-2024-52333HIGH7.8An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A spe...
CVE-2024-47796HIGH7.8An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially ...
CVE-2024-56301HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology ...
CVE-2024-56065HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: ...
CVE-2024-52938HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert recons...
CVE-2024-52937MEDIUM6.7Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-52936MEDIUM4.4Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data out...
CVE-2024-52935MEDIUM4.1Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-47897HIGH8.8Software installed and run as a non-privileged user may conduct improper GPU system calls resulting in platform instabil...
CVE-2024-47895HIGH7.1Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outs...
CVE-2024-47894HIGH7.1Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outs...
CVE-2024-51728——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now