2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51558CRITICAL9.8This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on it...
CVE-2024-51557MEDIUM6.5This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authentica...
CVE-2024-51556MEDIUM6.5This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response....
CVE-2024-36485HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
CVE-2024-10523MEDIUM4.6This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device f...
CVE-2024-10035CRITICAL9.8Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command...
CVE-2024-51661HIGH7.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingre...
CVE-2024-48878HIGH8.8Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
CVE-2024-10389HIGH7.5There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). ...
CVE-2024-38424HIGH7.8Memory corruption during GNSS HAL process initialization.
CVE-2024-38423HIGH7.8Memory corruption while processing GPU page table switch.
CVE-2024-38422HIGH7.8Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38421HIGH7.8Memory corruption while processing GPU commands.
CVE-2024-38419HIGH7.8Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
CVE-2024-38415HIGH7.8Memory corruption while handling session errors from firmware.
CVE-2024-38410HIGH7.8Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
CVE-2024-38409HIGH7.8Memory corruption while station LL statistic handling.
CVE-2024-38408CRITICAL9.1Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-38407HIGH7Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
CVE-2024-38406HIGH7Memory corruption while handling IOCTL calls in JPEG Encoder driver.
CVE-2024-38405MEDIUM6.5Transient DOS while processing the CU information from RNR IE.
CVE-2024-38403MEDIUM6.5Transient DOS while parsing BTM ML IE when per STA profile is not included.
CVE-2024-33068MEDIUM6.5Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-33033HIGH7.8Memory corruption while processing IOCTL calls to unmap the buffers.
CVE-2024-33032MEDIUM6.7Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now