2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45432HIGH7.5OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK B...
CVE-2024-45431MEDIUM5.3OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSD...
CVE-2024-47120MEDIUM6.8IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their...
CVE-2024-45671HIGH7.5IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algor...
CVE-2024-45669MEDIUM6.5IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of ...
CVE-2024-45325MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i...
CVE-2024-48341LOW3.7dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction....
CVE-2024-36354HIGH7.5Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r...
CVE-2024-36352HIGH8.4Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote...
CVE-2024-36346MEDIUM6Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen...
CVE-2024-36342HIGH8.8Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in ...
CVE-2024-36331LOW3.2Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN...
CVE-2024-36326HIGH8.4Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a...
CVE-2024-21970MEDIUM4.4Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt ...
CVE-2024-21947HIGH7.5Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary m...
CVE-2024-0028MEDIUM5.5In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permissio...
CVE-2024-21977LOW3.2Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDR...
CVE-2024-49731MEDIUM4In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new ...
CVE-2024-40664MEDIUM6.2In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s...
CVE-2024-49714HIGH7.8In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea...
CVE-2024-49739MEDIUM4In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to...
CVE-2024-43184MEDIUM6.1IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnera...
CVE-2024-34598MEDIUM5.5Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applicat...
CVE-2024-56190HIGH7.8In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T...
CVE-2024-56189MEDIUM6.5In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now