2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5412 | HIGH | 7.5 | 0.7% | Sep 3, 2024 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 cou... |
| CVE-2024-42060 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US... |
| CVE-2024-42059 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US... |
| CVE-2024-42058 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series... |
| CVE-2024-42057 | HIGH | 8.1 | 1.3% | Sep 3, 2024 | A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.3... |
| CVE-2024-1621 | HIGH | 7.5 | 0.4% | Sep 2, 2024 | The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compr... |
| CVE-2024-6921 | HIGH | 7.5 | 0.2% | Sep 2, 2024 | Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retriev... |
| CVE-2024-45388 | HIGH | 7.5 | 55.9% | Sep 2, 2024 | Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/ap... |
| CVE-2024-45311 | HIGH | 7.5 | 0.6% | Sep 2, 2024 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is... |
| CVE-2024-42471 | HIGH | 7.5 | 3.0% | Sep 2, 2024 | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch ... |
| CVE-2024-5148 | HIGH | 7.5 | 0.6% | Sep 2, 2024 | A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validat... |
| CVE-2024-38402 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. |
| CVE-2024-38401 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption while processing concurrent IOCTL calls. |
| CVE-2024-33060 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. |
| CVE-2024-33057 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing the multi-link element Control field when common information length check is missing before ... |
| CVE-2024-33054 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. |
| CVE-2024-33052 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. |
| CVE-2024-33051 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33050 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing... |
| CVE-2024-33048 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| CVE-2024-33047 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when the captureRead QDCM command is invoked from user-space. |
| CVE-2024-33045 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| CVE-2024-33042 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. |
| CVE-2024-33038 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. |
| CVE-2024-33035 | HIGH | 8.4 | 0.1% | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now