2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37355HIGH8.8Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalat...
CVE-2024-36274HIGH7.1Out-of-bounds write in the Intel(R) 800 Series Ethernet Driver for Intel(R) Ethernet Adapter Complete Driver Pack before...
CVE-2024-36262HIGH8.6Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user...
CVE-2024-32941HIGH7.9NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potenti...
CVE-2024-31858HIGH7.8Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated us...
CVE-2024-31155HIGH8.7Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentiall...
CVE-2024-29223HIGH7.8Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticat...
CVE-2024-29214HIGH8.7Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged use...
CVE-2024-28127HIGH8.7Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl...
CVE-2024-24582HIGH8.7Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to ...
CVE-2024-12673HIGH8.5An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devic...
CVE-2024-11628HIGH7.2In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties wi...
CVE-2024-9870HIGH8.8An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior...
CVE-2024-12629HIGH7.2In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within t...
CVE-2024-11343HIGH8.8In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can le...
CVE-2024-12251HIGH7.8In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through impro...
CVE-2024-57951HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hrtimers: Handle CPU state correctly on hotplug Co...
CVE-2024-13532HIGH7.5The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '...
CVE-2024-13480HIGH7.5The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edi...
CVE-2024-10960HIGH8.8The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-32838HIGH8.8SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before...
CVE-2024-13531HIGH7.5The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all ve...
CVE-2024-13528HIGH7.5The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versi...
CVE-2024-13490HIGH7.5The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship...
CVE-2024-13475HIGH7.5The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now