2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21970MEDIUM4.4Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt ...
CVE-2024-21947HIGH7.5Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary m...
CVE-2024-0028MEDIUM5.5In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permissio...
CVE-2024-21977LOW3.2Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDR...
CVE-2024-49731MEDIUM4In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new ...
CVE-2024-40664MEDIUM6.2In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s...
CVE-2024-49714HIGH7.8In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea...
CVE-2024-49739MEDIUM4In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to...
CVE-2024-43184MEDIUM6.1IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnera...
CVE-2024-34598MEDIUM5.5Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applicat...
CVE-2024-56190HIGH7.8In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T...
CVE-2024-56189MEDIUM6.5In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check...
CVE-2024-13073MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Ta...
CVE-2024-13071MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-...
CVE-2024-13068HIGH7.3Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: fro...
CVE-2024-13066MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - ...
CVE-2024-43166CRITICAL9.8Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef...
CVE-2024-43115HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s...
CVE-2024-13065MEDIUM6.3Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows...
CVE-2024-13064MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft My...
CVE-2024-13063MEDIUM6.8Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issu...
CVE-2024-32444CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue...
CVE-2024-49730HIGH7.8In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation...
CVE-2024-49728MEDIUM5.5In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused ...
CVE-2024-49722MEDIUM5.5In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now