2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51111 | MEDIUM | 4.1 | 0.3% | Jan 6, 2025 | Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web pag... |
| CVE-2024-31914 | MEDIUM | 6.4 | 0.2% | Jan 6, 2025 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored... |
| CVE-2024-31913 | MEDIUM | 5.4 | 0.2% | Jan 6, 2025 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored... |
| CVE-2024-8474 | HIGH | 7.5 | 0.5% | Jan 6, 2025 | OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in t... |
| CVE-2024-12997 | — | — | — | Jan 6, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-12996 | — | — | — | Jan 6, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-5594 | CRITICAL | 9.1 | 0.8% | Jan 6, 2025 | OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to ... |
| CVE-2024-12970 | LOW | 3.9 | 1.3% | Jan 6, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILG... |
| CVE-2024-45559 | MEDIUM | 5.5 | 0.1% | Jan 6, 2025 | Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend. |
| CVE-2024-45558 | HIGH | 7.5 | 0.4% | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without ch... |
| CVE-2024-45555 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows u... |
| CVE-2024-45553 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global... |
| CVE-2024-45550 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls. |
| CVE-2024-45548 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call. |
| CVE-2024-45547 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryp... |
| CVE-2024-45546 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space. |
| CVE-2024-45542 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
| CVE-2024-45541 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption when IOCTL call is invoked from user-space to read board data. |
| CVE-2024-43064 | MEDIUM | 4.7 | 0.1% | Jan 6, 2025 | Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers th... |
| CVE-2024-43063 | MEDIUM | 5.5 | 0.1% | Jan 6, 2025 | information disclosure while invoking the mailbox read API. |
| CVE-2024-33067 | MEDIUM | 5.5 | 0.1% | Jan 6, 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received ... |
| CVE-2024-33061 | MEDIUM | 5.5 | 0.1% | Jan 6, 2025 | Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel ... |
| CVE-2024-33059 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption while processing frame command IOCTL calls. |
| CVE-2024-33055 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption while invoking IOCTL calls to unmap the DMA buffers. |
| CVE-2024-33041 | HIGH | 7.8 | 0.1% | Jan 6, 2025 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now