2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43797MEDIUM4.3audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or ac...
CVE-2024-43792MEDIUM6.1Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 o...
CVE-2024-42471HIGH7.5actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch ...
CVE-2024-28100MEDIUM5.4eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular use...
CVE-2024-8004MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-7939MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an ...
CVE-2024-7938MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x thr...
CVE-2024-7932MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allow...
CVE-2024-5148HIGH7.5A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validat...
CVE-2024-38858MEDIUM6.1Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts...
CVE-2024-38402HIGH7.8Memory corruption while processing IOCTL call for getting group info.
CVE-2024-38401HIGH7.8Memory corruption while processing concurrent IOCTL calls.
CVE-2024-33060HIGH7.8Memory corruption when two threads try to map and unmap a single node simultaneously.
CVE-2024-33057HIGH7.5Transient DOS while parsing the multi-link element Control field when common information length check is missing before ...
CVE-2024-33054HIGH7.8Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
CVE-2024-33052HIGH7.8Memory corruption when user provides data for FM HCI command control operations.
CVE-2024-33051HIGH7.5Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33050HIGH7.5Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing...
CVE-2024-33048HIGH7.5Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2024-33047HIGH7.8Memory corruption when the captureRead QDCM command is invoked from user-space.
CVE-2024-33045HIGH7.8Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
CVE-2024-33043MEDIUM5.5Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33042HIGH7.8Memory corruption when Alternative Frequency offset value is set to 255.
CVE-2024-33038HIGH7.8Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
CVE-2024-33035HIGH8.4Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now