2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43086 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir... |
| CVE-2024-43085 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocki... |
| CVE-2024-43084 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to ... |
| CVE-2024-43083 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion.... |
| CVE-2024-43082 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy.... |
| CVE-2024-43081 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo... |
| CVE-2024-43080 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization.... |
| CVE-2024-40671 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a mi... |
| CVE-2024-40661 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due... |
| CVE-2024-40660 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a lo... |
| CVE-2024-34747 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This c... |
| CVE-2024-34729 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to... |
| CVE-2024-34719 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca... |
| CVE-2024-31337 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This... |
| CVE-2024-23715 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lea... |
| CVE-2024-9476 | MEDIUM | 5.1 | 0.2% | Nov 13, 2024 | A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re... |
| CVE-2024-9413 | HIGH | 8 | 0.4% | Nov 13, 2024 | The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, p... |
| CVE-2024-52292 | MEDIUM | 6.5 | 0.7% | Nov 13, 2024 | Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o... |
| CVE-2024-52291 | HIGH | 7.2 | 1.1% | Nov 13, 2024 | Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system v... |
| CVE-2024-51996 | HIGH | 7.5 | 0.6% | Nov 13, 2024 | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p... |
| CVE-2024-45594 | MEDIUM | 5.4 | 0.2% | Nov 13, 2024 | Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj... |
| CVE-2024-8049 | MEDIUM | 6.5 | 0.4% | Nov 13, 2024 | In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with un... |
| CVE-2024-7295 | MEDIUM | 6.2 | 0.1% | Nov 13, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an... |
| CVE-2024-52306 | CRITICAL | 9.8 | 0.6% | Nov 13, 2024 | FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data ... |
| CVE-2024-52305 | MEDIUM | 4.8 | 0.2% | Nov 13, 2024 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now