2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0043 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a lo... |
| CVE-2024-0042 | HIGH | 7.8 | 0.1% | May 7, 2024 | In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead ... |
| CVE-2024-0025 | HIGH | 7.8 | 0.1% | May 7, 2024 | In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error.... |
| CVE-2024-0024 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due ... |
| CVE-2024-34315 | HIGH | 7.5 | 0.7% | May 7, 2024 | CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the... |
| CVE-2024-25513 | HIGH | 7.8 | 0.3% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /Corporat... |
| CVE-2024-25512 | HIGH | 8.1 | 0.5% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bullet... |
| CVE-2024-33149 | HIGH | 8.1 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessLis... |
| CVE-2024-33148 | HIGH | 7.3 | 0.4% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list functio... |
| CVE-2024-33147 | HIGH | 8.8 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList... |
| CVE-2024-29207 | HIGH | 7.5 | 0.3% | May 7, 2024 | An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of t... |
| CVE-2024-29150 | HIGH | 8.8 | 0.5% | May 7, 2024 | An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu... |
| CVE-2024-29149 | HIGH | 7.4 | 0.2% | May 7, 2024 | An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu... |
| CVE-2024-33144 | HIGH | 8.8 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedT... |
| CVE-2024-33139 | HIGH | 7.5 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage fun... |
| CVE-2024-34523 | HIGH | 7.5 | 0.8% | May 7, 2024 | AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by usin... |
| CVE-2024-34342 | HIGH | 7.1 | 1.1% | May 7, 2024 | react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalS... |
| CVE-2024-34084 | HIGH | 7.5 | 0.6% | May 7, 2024 | Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerab... |
| CVE-2024-32664 | HIGH | 7.3 | 0.9% | May 7, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-32663 | HIGH | 7.5 | 1.0% | May 7, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-32371 | HIGH | 7.5 | 0.7% | May 7, 2024 | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their p... |
| CVE-2024-33782 | HIGH | 7.5 | 0.7% | May 7, 2024 | MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtens... |
| CVE-2024-33781 | HIGH | 7.5 | 0.7% | May 7, 2024 | MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.... |
| CVE-2024-29889 | HIGH | 8.1 | 63.2% | May 7, 2024 | GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injec... |
| CVE-2024-4600 | HIGH | 7.1 | 0.2% | May 7, 2024 | Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now