2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43369HIGH7.2Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versi...
CVE-2024-7843HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Aff...
CVE-2024-7842HIGH7.5A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0...
CVE-2024-7841HIGH7.5A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerabi...
CVE-2024-34743HIGH7.8In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the ...
CVE-2024-34741HIGH7.8In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be vis...
CVE-2024-34740HIGH7.8In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection d...
CVE-2024-34739HIGH7.8In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a ...
CVE-2024-34738HIGH7.8In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRea...
CVE-2024-34737HIGH7.8In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable a...
CVE-2024-34736HIGH7.8In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabl...
CVE-2024-34734HIGH7.8In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app ...
CVE-2024-34731HIGH7In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. T...
CVE-2024-34727HIGH7.5In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. Th...
CVE-2024-31333HIGH7.8In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could ...
CVE-2024-7868HIGH8.2In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT ...
CVE-2024-6456HIGH8.5AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privi...
CVE-2024-43367HIGH7.5Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0...
CVE-2024-43357HIGH8.6ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) s...
CVE-2024-22218HIGH8.8XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows...
CVE-2024-42987HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack-based buffer overflow vulnerability in the fromPptpUserAdd f...
CVE-2024-42986HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWa...
CVE-2024-42985HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function...
CVE-2024-42984HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter fun...
CVE-2024-42983HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan func...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now