2024 CVE Vulnerabilities

39,220 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-43634MEDIUM6.8Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43633MEDIUM6.5Windows Hyper-V Denial of Service Vulnerability
CVE-2024-43451MEDIUM6.5NTLM Hash Disclosure Spoofing Vulnerability
CVE-2024-43449MEDIUM6.8Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-38264MEDIUM5.9Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability
CVE-2024-38203MEDIUM5.5Windows Package Library Manager Information Disclosure Vulnerability
CVE-2024-21949MEDIUM5.5Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, po...
CVE-2024-9999MEDIUM6.5In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Tr...
CVE-2024-9843MEDIUM5.5A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia...
CVE-2024-51750MEDIUM5Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f...
CVE-2024-50336MEDIUM5.3matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerabl...
CVE-2024-49527MEDIUM5.5Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl...
CVE-2024-30133MEDIUM5.3HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not suff...
CVE-2024-11004MEDIUM6.1Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a...
CVE-2024-52296MEDIUM6.5libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp...
CVE-2024-47909MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2...
CVE-2024-47905MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2...
CVE-2024-47535MEDIUM5.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2024-10971MEDIUM4.3Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious auth...
CVE-2024-51566MEDIUM6.5The NVMe driver queue processing is vulernable to guest-induced infinite loops.
CVE-2024-51565MEDIUM6.5The hda driver is vulnerable to a buffer over-read from a guest-controlled value.
CVE-2024-51563MEDIUM6.5The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2024-51562MEDIUM6.5The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.
CVE-2024-39281MEDIUM5.3The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel...
CVE-2024-33660MEDIUM5.2An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now