2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-2175HIGH7.8An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Di...
CVE-2024-7145HIGH8.8The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 ...
CVE-2024-7146HIGH8.8The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin...
CVE-2024-7630HIGH7.5The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-7853HIGH8.8A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical...
CVE-2024-7849HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L...
CVE-2024-7845HIGH7.5A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by th...
CVE-2024-43378HIGH7.8calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who ins...
CVE-2024-43370HIGH7.2gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dict...
CVE-2024-43369HIGH7.2Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versi...
CVE-2024-7843HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Aff...
CVE-2024-7842HIGH7.5A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0...
CVE-2024-7841HIGH7.5A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerabi...
CVE-2024-34743HIGH7.8In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the ...
CVE-2024-34741HIGH7.8In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be vis...
CVE-2024-34740HIGH7.8In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection d...
CVE-2024-34739HIGH7.8In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a ...
CVE-2024-34738HIGH7.8In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRea...
CVE-2024-34737HIGH7.8In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable a...
CVE-2024-34736HIGH7.8In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabl...
CVE-2024-34734HIGH7.8In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app ...
CVE-2024-34731HIGH7In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. T...
CVE-2024-34727HIGH7.5In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. Th...
CVE-2024-31333HIGH7.8In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could ...
CVE-2024-7868HIGH8.2In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now