2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8642 | HIGH | 8.1 | 0.4% | Sep 11, 2024 | In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApi... |
| CVE-2024-8639 | HIGH | 8.8 | 0.3% | Sep 11, 2024 | Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially ... |
| CVE-2024-8638 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object co... |
| CVE-2024-8637 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentia... |
| CVE-2024-8636 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit h... |
| CVE-2024-7609 | HIGH | 7.5 | 0.5% | Sep 11, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTE... |
| CVE-2024-45788 | HIGH | 7.5 | 0.5% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API e... |
| CVE-2024-45327 | HIGH | 7.5 | 0.3% | Sep 11, 2024 | An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 t... |
| CVE-2024-7626 | HIGH | 8.1 | 0.8% | Sep 11, 2024 | The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar... |
| CVE-2024-43690 | HIGH | 8 | 0.6% | Sep 11, 2024 | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allo... |
| CVE-2024-21529 | HIGH | 8.8 | 0.6% | Sep 11, 2024 | Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user ... |
| CVE-2024-8253 | HIGH | 8.8 | 9.6% | Sep 11, 2024 | The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to ... |
| CVE-2024-40662 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This co... |
| CVE-2024-40658 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow.... |
| CVE-2024-40657 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users du... |
| CVE-2024-40655 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use p... |
| CVE-2024-40654 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati... |
| CVE-2024-40652 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is pro... |
| CVE-2024-40650 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could ... |
| CVE-2024-31336 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper inp... |
| CVE-2024-23716 | HIGH | 7 | 0.1% | Sep 11, 2024 | In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead ... |
| CVE-2024-8322 | HIGH | 8.8 | 1.1% | Sep 10, 2024 | Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote auth... |
| CVE-2024-8321 | HIGH | 8.6 | 1.8% | Sep 10, 2024 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ... |
| CVE-2024-8190 | HIGH | 7.2 | 89.0% | Sep 10, 2024 | An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo... |
| CVE-2024-8012 | HIGH | 7.8 | 0.3% | Sep 10, 2024 | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now