2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56442 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vul... |
| CVE-2024-56440 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may ca... |
| CVE-2024-56439 | HIGH | 7.5 | 0.1% | Jan 8, 2025 | Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-56438 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerabi... |
| CVE-2024-56437 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of t... |
| CVE-2024-56436 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-56435 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-56434 | HIGH | 7.5 | 0.1% | Jan 8, 2025 | UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause servi... |
| CVE-2024-53522 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe ... |
| CVE-2024-40427 | HIGH | 7.9 | 0.3% | Jan 7, 2025 | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability... |
| CVE-2024-55413 | HIGH | 7.8 | 0.2% | Jan 7, 2025 | A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users ... |
| CVE-2024-55412 | HIGH | 7.8 | 0.2% | Jan 7, 2025 | A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to... |
| CVE-2024-55411 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and ... |
| CVE-2024-54007 | HIGH | 7.2 | 1.6% | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead... |
| CVE-2024-54006 | HIGH | 7.2 | 1.6% | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead... |
| CVE-2024-8361 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length tr... |
| CVE-2024-55555 | HIGH | 8.8 | 6.5% | Jan 7, 2025 | Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_... |
| CVE-2024-40749 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | Improper Access Controls allows access to protected views. |
| CVE-2024-40748 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. |
| CVE-2024-12430 | HIGH | 7.3 | 0.3% | Jan 7, 2025 | An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exist... |
| CVE-2024-56056 | HIGH | 7.1 | 0.4% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleC... |
| CVE-2024-55008 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent... |
| CVE-2024-53800 | HIGH | 8.1 | 0.7% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-53345 | HIGH | 8.8 | 1.3% | Jan 7, 2025 | An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to ex... |
| CVE-2024-48245 | HIGH | 7.2 | 1.0% | Jan 7, 2025 | Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in var... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now