2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34614HIGH7.8Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.
CVE-2024-34613MEDIUM5.5Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive infor...
CVE-2024-34612HIGH7.8Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary...
CVE-2024-34611MEDIUM5.5Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive informati...
CVE-2024-34610MEDIUM5.5Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access prot...
CVE-2024-34609MEDIUM5.5Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restriction...
CVE-2024-34608MEDIUM5.5Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restri...
CVE-2024-34607MEDIUM5.5Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrict...
CVE-2024-34606MEDIUM5.5Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restricti...
CVE-2024-34605MEDIUM5.5Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restric...
CVE-2024-34604MEDIUM5.5Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions...
CVE-2024-38206MEDIUM6.5An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak s...
CVE-2024-38166MEDIUM6.1An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamic...
CVE-2024-7550HIGH8.8Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-7536HIGH8.8Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap...
CVE-2024-7535HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially expl...
CVE-2024-7534HIGH8.8Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit ...
CVE-2024-7533HIGH8.8Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploi...
CVE-2024-7532HIGH8.8Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially ex...
CVE-2024-42219HIGH7.81Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communic...
CVE-2024-42218MEDIUM4.71Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific securi...
CVE-2024-41270CRITICAL9.1An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data du...
CVE-2024-42400MEDIUM5.3Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI proto...
CVE-2024-42399MEDIUM5.3Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI proto...
CVE-2024-42398MEDIUM5.3Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI proto...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now