2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8642HIGH8.1In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApi...
CVE-2024-8639HIGH8.8Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially ...
CVE-2024-8638HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object co...
CVE-2024-8637HIGH8.8Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentia...
CVE-2024-8636HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit h...
CVE-2024-7609HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTE...
CVE-2024-45788HIGH7.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API e...
CVE-2024-45327HIGH7.5An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 t...
CVE-2024-7626HIGH8.1The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar...
CVE-2024-43690HIGH8Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allo...
CVE-2024-21529HIGH8.8Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user ...
CVE-2024-8253HIGH8.8The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to ...
CVE-2024-40662HIGH7.8In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This co...
CVE-2024-40658HIGH7.8In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow....
CVE-2024-40657HIGH7.8In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users du...
CVE-2024-40655HIGH7.8In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use p...
CVE-2024-40654HIGH7.8In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati...
CVE-2024-40652HIGH7.8In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is pro...
CVE-2024-40650HIGH7.8In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could ...
CVE-2024-31336HIGH7.8In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper inp...
CVE-2024-23716HIGH7In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead ...
CVE-2024-8322HIGH8.8Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote auth...
CVE-2024-8321HIGH8.6Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ...
CVE-2024-8190HIGH7.2An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo...
CVE-2024-8012HIGH7.8An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now