2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-56442HIGH7.5Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vul...
CVE-2024-56440HIGH7.5Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may ca...
CVE-2024-56439HIGH7.5Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability...
CVE-2024-56438HIGH7.5Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerabi...
CVE-2024-56437HIGH7.5Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of t...
CVE-2024-56436HIGH7.5Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability...
CVE-2024-56435HIGH7.5Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability...
CVE-2024-56434HIGH7.5UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause servi...
CVE-2024-53522HIGH7.5Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe ...
CVE-2024-40427HIGH7.9Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability...
CVE-2024-55413HIGH7.8A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users ...
CVE-2024-55412HIGH7.8A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to...
CVE-2024-55411HIGH8.8An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and ...
CVE-2024-54007HIGH7.2Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead...
CVE-2024-54006HIGH7.2Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead...
CVE-2024-8361HIGH7.5In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length tr...
CVE-2024-55555HIGH8.8Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_...
CVE-2024-40749HIGH7.5Improper Access Controls allows access to protected views.
CVE-2024-40748HIGH7.5Lack of output escaping in the id attribute of menu lists.
CVE-2024-12430HIGH7.3An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exist...
CVE-2024-56056HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleC...
CVE-2024-55008HIGH7.5JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent...
CVE-2024-53800HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-53345HIGH8.8An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to ex...
CVE-2024-48245HIGH7.2Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in var...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now