2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43771 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2024-43770 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co... |
| CVE-2024-43765 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou... |
| CVE-2024-43096 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could... |
| CVE-2024-43095 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This co... |
| CVE-2024-34730 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in... |
| CVE-2024-24428 | HIGH | 7.5 | 0.5% | Jan 21, 2025 | A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv... |
| CVE-2024-24427 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service ... |
| CVE-2024-24424 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321... |
| CVE-2024-24423 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24422 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24420 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f... |
| CVE-2024-24419 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24418 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24417 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24416 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-51941 | HIGH | 8.8 | 1.4% | Jan 21, 2025 | A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users... |
| CVE-2024-24451 | HIGH | 7.5 | 1.0% | Jan 21, 2025 | A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2... |
| CVE-2024-24444 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows... |
| CVE-2024-24442 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.... |
| CVE-2024-57542 | HIGH | 8.8 | 1.7% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_bt... |
| CVE-2024-57539 | HIGH | 8.2 | 1.3% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail. |
| CVE-2024-57536 | HIGH | 8 | 1.4% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status. |
| CVE-2024-57036 | HIGH | 8.1 | 0.5% | Jan 21, 2025 | TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main f... |
| CVE-2024-53829 | HIGH | 8.2 | 0.2% | Jan 21, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now