2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31325 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This... |
| CVE-2024-31324 | HIGH | 7.3 | 0.1% | Jul 9, 2024 | In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity i... |
| CVE-2024-31323 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjack... |
| CVE-2024-31322 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Se... |
| CVE-2024-31320 | HIGH | 7.8 | 0.3% | Jul 9, 2024 | In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association withou... |
| CVE-2024-31319 | HIGH | 7.8 | 0.2% | Jul 9, 2024 | In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user da... |
| CVE-2024-31318 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to... |
| CVE-2024-31317 | HIGH | 7.8 | 0.8% | Jul 9, 2024 | In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECU... |
| CVE-2024-31316 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch du... |
| CVE-2024-31315 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the De... |
| CVE-2024-31313 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check... |
| CVE-2024-31311 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. T... |
| CVE-2024-31310 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service ... |
| CVE-2024-23711 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in ... |
| CVE-2024-23698 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In RGXFWChangeOSidPriority of rgxfwutils.c, there is a possible arbitrary code execution due to a missing bounds check. ... |
| CVE-2024-23697 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could ... |
| CVE-2024-23696 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could le... |
| CVE-2024-23695 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In CacheOpPMRExec of cache_km.c, there is a possible out of bounds write due to an integer overflow. This could lead to ... |
| CVE-2024-39063 | HIGH | 8.8 | 0.3% | Jul 9, 2024 | Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed... |
| CVE-2024-37872 | HIGH | 8.1 | 0.5% | Jul 9, 2024 | SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute ... |
| CVE-2024-37871 | HIGH | 8.2 | 0.5% | Jul 9, 2024 | SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 all... |
| CVE-2024-34139 | HIGH | 7.8 | 0.4% | Jul 9, 2024 | Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that co... |
| CVE-2024-29153 | HIGH | 8.1 | 0.4% | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Ex... |
| CVE-2024-20785 | HIGH | 7.8 | 0.4% | Jul 9, 2024 | InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c... |
| CVE-2024-20783 | HIGH | 7.8 | 0.4% | Jul 9, 2024 | InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now