2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-40657HIGH7.8In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users du...
CVE-2024-40655HIGH7.8In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use p...
CVE-2024-40654HIGH7.8In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati...
CVE-2024-40652HIGH7.8In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is pro...
CVE-2024-40650HIGH7.8In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could ...
CVE-2024-31336HIGH7.8In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper inp...
CVE-2024-23716HIGH7In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead ...
CVE-2024-8322HIGH8.8Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote auth...
CVE-2024-8321HIGH8.6Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ...
CVE-2024-8190HIGH7.2An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo...
CVE-2024-8012HIGH7.8An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19...
CVE-2024-44107HIGH7.8DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local aut...
CVE-2024-44106HIGH7.8Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0...
CVE-2024-44105HIGH7.8Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 202...
CVE-2024-44104HIGH7.8An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Iva...
CVE-2024-44103HIGH7.8DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local aut...
CVE-2024-8504HIGH8.8An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user....
CVE-2024-8232HIGH8.7SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious f...
CVE-2024-44871HIGH7.2An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a...
CVE-2024-44667HIGH8Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to In...
CVE-2024-43495HIGH7.3Windows libarchive Remote Code Execution Vulnerability
CVE-2024-43492HIGH7.8Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2024-43479HIGH8.5Microsoft Power Automate Desktop Remote Code Execution Vulnerability
CVE-2024-43475HIGH7.3Microsoft Windows Admin Center Information Disclosure Vulnerability
CVE-2024-43474HIGH7.5Microsoft SQL Server Information Disclosure Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now