2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5792 | HIGH | 8.8 | 0.5% | Jul 10, 2024 | The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all... |
| CVE-2024-6433 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files... |
| CVE-2024-32670 | HIGH | 7 | 0.2% | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes ... |
| CVE-2024-21417 | HIGH | 8.8 | 0.4% | Jul 10, 2024 | Windows Text Services Framework Elevation of Privilege Vulnerability |
| CVE-2024-39883 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2024-39882 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a... |
| CVE-2024-39881 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption cond... |
| CVE-2024-39880 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2024-39069 | HIGH | 7.8 | 0.6% | Jul 9, 2024 | An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hij... |
| CVE-2024-36676 | HIGH | 7.5 | 0.6% | Jul 9, 2024 | Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targ... |
| CVE-2024-35154 | HIGH | 7.2 | 1.2% | Jul 9, 2024 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to t... |
| CVE-2024-37829 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafte... |
| CVE-2024-34726 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This co... |
| CVE-2024-34725 | HIGH | 7 | 0.1% | Jul 9, 2024 | In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi... |
| CVE-2024-34724 | HIGH | 7 | 0.1% | Jul 9, 2024 | In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead... |
| CVE-2024-34723 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from back... |
| CVE-2024-34722 | HIGH | 8.8 | 0.3% | Jul 9, 2024 | In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect imp... |
| CVE-2024-34720 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, ... |
| CVE-2024-31339 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lea... |
| CVE-2024-31335 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in th... |
| CVE-2024-31334 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error ... |
| CVE-2024-31332 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing ... |
| CVE-2024-31331 | HIGH | 7.3 | 0.1% | Jul 9, 2024 | In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic ... |
| CVE-2024-31327 | HIGH | 7 | 0.1% | Jul 9, 2024 | In multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race condition. This could... |
| CVE-2024-31326 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic erro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now