2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43086MEDIUM5.5In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir...
CVE-2024-43085HIGH7.8In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocki...
CVE-2024-43084MEDIUM5.5In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to ...
CVE-2024-43083MEDIUM5.5In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion....
CVE-2024-43082MEDIUM5.5In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy....
CVE-2024-43081HIGH7.8In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo...
CVE-2024-43080HIGH7.8In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization....
CVE-2024-40671HIGH7.8In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a mi...
CVE-2024-40661HIGH7.8In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due...
CVE-2024-40660HIGH7.8In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a lo...
CVE-2024-34747HIGH7.8In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This c...
CVE-2024-34729HIGH7.8In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to...
CVE-2024-34719HIGH7.8In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca...
CVE-2024-31337HIGH7.8In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This...
CVE-2024-23715HIGH7.8In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lea...
CVE-2024-9476MEDIUM5.1A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re...
CVE-2024-9413HIGH8The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, p...
CVE-2024-52292MEDIUM6.5Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o...
CVE-2024-52291HIGH7.2Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system v...
CVE-2024-51996HIGH7.5Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p...
CVE-2024-45594MEDIUM5.4Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj...
CVE-2024-8049MEDIUM6.5In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with un...
CVE-2024-7295MEDIUM6.2In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an...
CVE-2024-52306CRITICAL9.8FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data ...
CVE-2024-52305MEDIUM4.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now