2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40659MEDIUM5.5In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore...
CVE-2024-40658HIGH7.8In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow....
CVE-2024-40657HIGH7.8In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users du...
CVE-2024-40656MEDIUM5.5In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across user...
CVE-2024-40655HIGH7.8In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use p...
CVE-2024-40654HIGH7.8In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati...
CVE-2024-40652HIGH7.8In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is pro...
CVE-2024-40650HIGH7.8In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could ...
CVE-2024-31336HIGH7.8In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper inp...
CVE-2024-23716HIGH7In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead ...
CVE-2024-45597MEDIUM5.3Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to ht...
CVE-2024-8441MEDIUM6.7An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local auth...
CVE-2024-8322HIGH8.8Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote auth...
CVE-2024-8321HIGH8.6Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ...
CVE-2024-8320MEDIUM5.3Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ...
CVE-2024-8191CRITICAL9.8SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unau...
CVE-2024-8190HIGH7.2An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo...
CVE-2024-8012HIGH7.8An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19...
CVE-2024-44107HIGH7.8DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local aut...
CVE-2024-44106HIGH7.8Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0...
CVE-2024-44105HIGH7.8Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 202...
CVE-2024-44104HIGH7.8An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Iva...
CVE-2024-44103HIGH7.8DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local aut...
CVE-2024-8655MEDIUM6.9A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unk...
CVE-2024-8504HIGH8.8An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now