2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38402HIGH7.8Memory corruption while processing IOCTL call for getting group info.
CVE-2024-38401HIGH7.8Memory corruption while processing concurrent IOCTL calls.
CVE-2024-33060HIGH7.8Memory corruption when two threads try to map and unmap a single node simultaneously.
CVE-2024-33057HIGH7.5Transient DOS while parsing the multi-link element Control field when common information length check is missing before ...
CVE-2024-33054HIGH7.8Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
CVE-2024-33052HIGH7.8Memory corruption when user provides data for FM HCI command control operations.
CVE-2024-33051HIGH7.5Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33050HIGH7.5Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing...
CVE-2024-33048HIGH7.5Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2024-33047HIGH7.8Memory corruption when the captureRead QDCM command is invoked from user-space.
CVE-2024-33045HIGH7.8Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
CVE-2024-33042HIGH7.8Memory corruption when Alternative Frequency offset value is set to 255.
CVE-2024-33038HIGH7.8Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
CVE-2024-33035HIGH8.4Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
CVE-2024-23365HIGH8.4Memory corruption while releasing shared resources in MinkSocket listener thread.
CVE-2024-23364HIGH7.5Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Eleme...
CVE-2024-23362HIGH7.1Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359HIGH8.2Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23358HIGH7.5Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-7871HIGH8.7SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenti...
CVE-2024-43776HIGH8.8SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated us...
CVE-2024-43775HIGH8.8SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authe...
CVE-2024-43774HIGH8.8SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow...
CVE-2024-41160HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-41157HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now