2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-29787HIGH7.8In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free....
CVE-2024-29784HIGH7.8In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This coul...
CVE-2024-29781HIGH7.5In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper inpu...
CVE-2024-5950HIGH8.8Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. Th...
CVE-2024-5948HIGH8.8Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vul...
CVE-2024-5924HIGH8.8Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypas...
CVE-2024-4696HIGH7.5A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow op...
CVE-2024-37633HIGH8.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCf...
CVE-2024-37631HIGH8.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function Uplo...
CVE-2024-36587HIGH7.8Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to ...
CVE-2024-36586HIGH8.8An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuard...
CVE-2024-38285HIGH7Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.
CVE-2024-38284HIGH8.7Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a rep...
CVE-2024-38282HIGH8.5Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes t...
CVE-2024-37630HIGH8.8D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attac...
CVE-2024-37029HIGH7.8Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to ...
CVE-2024-37022HIGH7.8Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipul...
CVE-2024-36760HIGH7.5A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs ...
CVE-2024-32504HIGH7.8An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ...
CVE-2024-31956HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length...
CVE-2024-29169HIGH8.1Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST A...
CVE-2024-37306HIGH7.1Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting i...
CVE-2024-37164HIGH8.5Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allow...
CVE-2024-29168HIGH8.8Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST ...
CVE-2024-36396HIGH8.8Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now