2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43769 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallat... |
| CVE-2024-43768 | HIGH | 7.8 | 0.2% | Jan 3, 2025 | In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead... |
| CVE-2024-43767 | HIGH | 8.8 | 0.4% | Jan 3, 2025 | In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input valida... |
| CVE-2024-43764 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could l... |
| CVE-2024-43762 | HIGH | 7.8 | 0.2% | Jan 3, 2025 | In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in t... |
| CVE-2024-43097 | HIGH | 7.8 | 0.3% | Jan 3, 2025 | In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead ... |
| CVE-2024-43077 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In DevmemValidateFlags of devicemem_server.c , there is a possible out of bounds write due to memory corruption. This co... |
| CVE-2024-8447 | MEDIUM | 5.9 | 0.6% | Jan 2, 2025 | A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution... |
| CVE-2024-48197 | MEDIUM | 4.7 | 0.4% | Jan 2, 2025 | Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the... |
| CVE-2024-56199 | HIGH | 7.6 | 0.4% | Jan 2, 2025 | phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an att... |
| CVE-2024-11717 | MEDIUM | 6.3 | 0.6% | Jan 2, 2025 | Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When... |
| CVE-2024-11716 | MEDIUM | 5.3 | 11.7% | Jan 2, 2025 | While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in log... |
| CVE-2024-9950 | HIGH | 7.8 | 0.3% | Jan 2, 2025 | A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance... |
| CVE-2024-56414 | MEDIUM | 5.5 | 0.1% | Jan 2, 2025 | Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (W... |
| CVE-2024-56413 | MEDIUM | 6.1 | 0.2% | Jan 2, 2025 | Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows... |
| CVE-2024-55543 | HIGH | 7.8 | 0.2% | Jan 2, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-55542 | MEDIUM | 4.4 | 0.2% | Jan 2, 2025 | Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are aff... |
| CVE-2024-55541 | MEDIUM | 6.1 | 0.3% | Jan 2, 2025 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ... |
| CVE-2024-55540 | HIGH | 7.8 | 0.2% | Jan 2, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-12907 | MEDIUM | 5.3 | 0.4% | Jan 2, 2025 | Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parame... |
| CVE-2024-56137 | HIGH | 7.2 | 0.8% | Jan 2, 2025 | MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large ... |
| CVE-2024-55538 | MEDIUM | 4 | 0.2% | Jan 2, 2025 | Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image ... |
| CVE-2024-49385 | MEDIUM | 5.5 | 0.1% | Jan 2, 2025 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True I... |
| CVE-2024-38732 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue ... |
| CVE-2024-38731 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze allows Cross Site Request Forgery.This issue affects ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now