2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34739HIGH7.8In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a ...
CVE-2024-34738HIGH7.8In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRea...
CVE-2024-34737HIGH7.8In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable a...
CVE-2024-34736HIGH7.8In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabl...
CVE-2024-34734HIGH7.8In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app ...
CVE-2024-34731HIGH7In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. T...
CVE-2024-34727HIGH7.5In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. Th...
CVE-2024-31333HIGH7.8In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could ...
CVE-2024-7868HIGH8.2In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT ...
CVE-2024-7839CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part o...
CVE-2024-6456HIGH8.5AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privi...
CVE-2024-43367HIGH7.5Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0...
CVE-2024-43366CRITICAL9.1zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incomplet...
CVE-2024-42488MEDIUM6.8Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and...
CVE-2024-42487MEDIUM4.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1...
CVE-2024-7867MEDIUM6.2In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
CVE-2024-7866MEDIUM5.5In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
CVE-2024-7838CRITICAL9.8A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by th...
CVE-2024-43357HIGH8.6ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) s...
CVE-2024-42757CRITICAL9.8Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via ...
CVE-2024-42476MEDIUM6.5In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `st...
CVE-2024-42475MEDIUM6.5In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not ...
CVE-2024-42472CRITICAL10Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious ...
CVE-2024-27731MEDIUM6.1Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t...
CVE-2024-27730CRITICAL9.8Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and e...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now