2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25565MEDIUM4.8Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated us...
CVE-2024-25563MEDIUM4.6Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before vers...
CVE-2024-24985HIGH8.5Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to poten...
CVE-2024-24984MEDIUM6.8Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an...
CVE-2024-23919MEDIUM5.3Improper buffer restrictions in some Intel(R) Graphics software may allow an authenticated user to potentially enable es...
CVE-2024-23918HIGH8.8Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX ma...
CVE-2024-23312MEDIUM6.7Uncontrolled search path for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow...
CVE-2024-23198MEDIUM6.8Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products ...
CVE-2024-22185HIGH8.5Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to p...
CVE-2024-21853MEDIUM5.7Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors m...
CVE-2024-21850HIGH8.3Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1...
CVE-2024-21820HIGH8.5Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SG...
CVE-2024-21808MEDIUM4.2Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to pote...
CVE-2024-21799HIGH7.1Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user ...
CVE-2024-21783MEDIUM4.8Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially ena...
CVE-2024-11193MEDIUM6.5An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext...
CVE-2024-42834MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC...
CVE-2024-40443MEDIUM4.3SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to...
CVE-2024-49379MEDIUM5.3Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected...
CVE-2024-43093HIGH7.3In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prev...
CVE-2024-43091CRITICAL9.8In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could ...
CVE-2024-43090MEDIUM5In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to l...
CVE-2024-43089HIGH7.8In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission ...
CVE-2024-43088HIGH7.8In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to an...
CVE-2024-43087HIGH7.8In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled access...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now