2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5792HIGH8.8The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all...
CVE-2024-6433HIGH7.5The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files...
CVE-2024-32670HIGH7Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes ...
CVE-2024-21417HIGH8.8Windows Text Services Framework Elevation of Privilege Vulnerability
CVE-2024-39883HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2024-39882HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a...
CVE-2024-39881HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption cond...
CVE-2024-39880HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2024-39069HIGH7.8An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hij...
CVE-2024-36676HIGH7.5Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targ...
CVE-2024-35154HIGH7.2IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to t...
CVE-2024-37829HIGH8.8An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafte...
CVE-2024-34726HIGH7.8In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This co...
CVE-2024-34725HIGH7In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi...
CVE-2024-34724HIGH7In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead...
CVE-2024-34723HIGH7.8In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from back...
CVE-2024-34722HIGH8.8In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect imp...
CVE-2024-34720HIGH7.8In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, ...
CVE-2024-31339HIGH7.8In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lea...
CVE-2024-31335HIGH7.8In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in th...
CVE-2024-31334HIGH7.8In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error ...
CVE-2024-31332HIGH7.8In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing ...
CVE-2024-31331HIGH7.3In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic ...
CVE-2024-31327HIGH7In multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race condition. This could...
CVE-2024-31326HIGH7.8In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic erro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now