2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-0043HIGH7.8In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a lo...
CVE-2024-0042HIGH7.8In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead ...
CVE-2024-0025HIGH7.8In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error....
CVE-2024-0024HIGH7.8In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due ...
CVE-2024-34315HIGH7.5CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the...
CVE-2024-25513HIGH7.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /Corporat...
CVE-2024-25512HIGH8.1RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bullet...
CVE-2024-33149HIGH8.1J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessLis...
CVE-2024-33148HIGH7.3J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list functio...
CVE-2024-33147HIGH8.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList...
CVE-2024-29207HIGH7.5An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of t...
CVE-2024-29150HIGH8.8An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu...
CVE-2024-29149HIGH7.4An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu...
CVE-2024-33144HIGH8.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedT...
CVE-2024-33139HIGH7.5J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage fun...
CVE-2024-34523HIGH7.5AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by usin...
CVE-2024-34342HIGH7.1react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalS...
CVE-2024-34084HIGH7.5Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerab...
CVE-2024-32664HIGH7.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-32663HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-32371HIGH7.5An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their p...
CVE-2024-33782HIGH7.5MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtens...
CVE-2024-33781HIGH7.5MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream....
CVE-2024-29889HIGH8.1GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injec...
CVE-2024-4600HIGH7.1Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now