2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52460 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in atarapay AtaraPay ... |
| CVE-2024-52459 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni Chamele... |
| CVE-2024-52458 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zaymund TM Islamic... |
| CVE-2024-52457 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in youneeq Youneeq Re... |
| CVE-2024-52456 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoets Awesome Stu... |
| CVE-2024-52455 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goqsystem GoQSmile... |
| CVE-2024-52454 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goqsystem GoQMieru... |
| CVE-2024-52453 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in photonicgnostic Li... |
| CVE-2024-52452 | HIGH | 7.1 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX L... |
| CVE-2024-51900 | MEDIUM | 5.9 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in James Hunt What Wo... |
| CVE-2024-12015 | HIGH | 7.7 | 0.5% | Dec 2, 2024 | The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' para... |
| CVE-2024-43053 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information. |
| CVE-2024-43052 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while processing API calls to NPU with invalid input. |
| CVE-2024-43050 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. |
| CVE-2024-43049 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver. |
| CVE-2024-43048 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption when invalid input is passed to invoke GPU Headroom API call. |
| CVE-2024-33063 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside w... |
| CVE-2024-33056 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-33053 | MEDIUM | 6.7 | 0.1% | Dec 2, 2024 | Memory corruption when multiple threads try to unregister the CVP buffer at the same time. |
| CVE-2024-33044 | HIGH | 7.8 | 0.1% | Dec 2, 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
| CVE-2024-33040 | HIGH | 7 | 0.1% | Dec 2, 2024 | Memory corruption while invoking redundant release command to release one buffer from user space as race condition can o... |
| CVE-2024-33039 | MEDIUM | 6.7 | 0.1% | Dec 2, 2024 | Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not valid... |
| CVE-2024-33037 | MEDIUM | 6.1 | 0.1% | Dec 2, 2024 | Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC... |
| CVE-2024-33036 | MEDIUM | 6.7 | 0.1% | Dec 2, 2024 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in ... |
| CVE-2024-10490 | HIGH | 8.4 | 0.5% | Dec 2, 2024 | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now