2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25565 | MEDIUM | 4.8 | 0.2% | Nov 13, 2024 | Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated us... |
| CVE-2024-25563 | MEDIUM | 4.6 | 0.2% | Nov 13, 2024 | Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before vers... |
| CVE-2024-24985 | HIGH | 8.5 | 0.2% | Nov 13, 2024 | Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to poten... |
| CVE-2024-24984 | MEDIUM | 6.8 | 0.3% | Nov 13, 2024 | Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an... |
| CVE-2024-23919 | MEDIUM | 5.3 | 0.2% | Nov 13, 2024 | Improper buffer restrictions in some Intel(R) Graphics software may allow an authenticated user to potentially enable es... |
| CVE-2024-23918 | HIGH | 8.8 | 0.3% | Nov 13, 2024 | Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX ma... |
| CVE-2024-23312 | MEDIUM | 6.7 | 0.2% | Nov 13, 2024 | Uncontrolled search path for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow... |
| CVE-2024-23198 | MEDIUM | 6.8 | 0.2% | Nov 13, 2024 | Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products ... |
| CVE-2024-22185 | HIGH | 8.5 | 0.1% | Nov 13, 2024 | Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to p... |
| CVE-2024-21853 | MEDIUM | 5.7 | 0.2% | Nov 13, 2024 | Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors m... |
| CVE-2024-21850 | HIGH | 8.3 | 0.2% | Nov 13, 2024 | Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1... |
| CVE-2024-21820 | HIGH | 8.5 | 0.2% | Nov 13, 2024 | Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SG... |
| CVE-2024-21808 | MEDIUM | 4.2 | 0.2% | Nov 13, 2024 | Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to pote... |
| CVE-2024-21799 | HIGH | 7.1 | 0.7% | Nov 13, 2024 | Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user ... |
| CVE-2024-21783 | MEDIUM | 4.8 | 0.2% | Nov 13, 2024 | Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially ena... |
| CVE-2024-11193 | MEDIUM | 6.5 | 0.3% | Nov 13, 2024 | An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext... |
| CVE-2024-42834 | MEDIUM | 5.4 | 0.5% | Nov 13, 2024 | A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC... |
| CVE-2024-40443 | MEDIUM | 4.3 | 0.7% | Nov 13, 2024 | SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to... |
| CVE-2024-49379 | MEDIUM | 5.3 | 1.2% | Nov 13, 2024 | Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected... |
| CVE-2024-43093 | HIGH | 7.3 | 0.7% | Nov 13, 2024 | In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prev... |
| CVE-2024-43091 | CRITICAL | 9.8 | 0.5% | Nov 13, 2024 | In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could ... |
| CVE-2024-43090 | MEDIUM | 5 | 0.2% | Nov 13, 2024 | In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to l... |
| CVE-2024-43089 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission ... |
| CVE-2024-43088 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to an... |
| CVE-2024-43087 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled access... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now