2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53835 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with... |
| CVE-2024-53834 | HIGH | 7.5 | 0.3% | Jan 3, 2025 | In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect boun... |
| CVE-2024-53833 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validat... |
| CVE-2024-47032 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow... |
| CVE-2024-11624 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of priv... |
| CVE-2024-43769 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallat... |
| CVE-2024-43768 | HIGH | 7.8 | 0.2% | Jan 3, 2025 | In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead... |
| CVE-2024-43767 | HIGH | 8.8 | 0.4% | Jan 3, 2025 | In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input valida... |
| CVE-2024-43764 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could l... |
| CVE-2024-43762 | HIGH | 7.8 | 0.2% | Jan 3, 2025 | In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in t... |
| CVE-2024-43097 | HIGH | 7.8 | 0.3% | Jan 3, 2025 | In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead ... |
| CVE-2024-43077 | HIGH | 7.8 | 0.1% | Jan 3, 2025 | In DevmemValidateFlags of devicemem_server.c , there is a possible out of bounds write due to memory corruption. This co... |
| CVE-2024-56199 | HIGH | 7.6 | 0.4% | Jan 2, 2025 | phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an att... |
| CVE-2024-9950 | HIGH | 7.8 | 0.3% | Jan 2, 2025 | A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance... |
| CVE-2024-55543 | HIGH | 7.8 | 0.2% | Jan 2, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-55540 | HIGH | 7.8 | 0.2% | Jan 2, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-56137 | HIGH | 7.2 | 0.8% | Jan 2, 2025 | MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large ... |
| CVE-2024-13111 | HIGH | 8.1 | 0.8% | Jan 2, 2025 | A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination Syste... |
| CVE-2024-13110 | HIGH | 7.5 | 0.6% | Jan 2, 2025 | A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examinati... |
| CVE-2024-56014 | HIGH | 7.1 | 0.3% | Jan 2, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markyis Cool Olivi... |
| CVE-2024-39623 | HIGH | 8.8 | 0.3% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This ... |
| CVE-2024-56267 | HIGH | 7.1 | 0.3% | Jan 2, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in html5maps Interact... |
| CVE-2024-56266 | HIGH | 8.8 | 0.3% | Jan 2, 2025 | Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-... |
| CVE-2024-56250 | HIGH | 7.6 | 0.4% | Jan 2, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Greg Ross Just Wri... |
| CVE-2024-56247 | HIGH | 7.2 | 0.5% | Jan 2, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now