2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40498 | CRITICAL | 9.8 | 1.0% | Aug 5, 2024 | SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbit... |
| CVE-2024-40531 | HIGH | 8.8 | 0.4% | Aug 5, 2024 | A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users... |
| CVE-2024-40530 | HIGH | 7.5 | 0.4% | Aug 5, 2024 | A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access cont... |
| CVE-2024-21980 | HIGH | 7.9 | 0.4% | Aug 5, 2024 | Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a g... |
| CVE-2024-21978 | HIGH | 7.9 | 0.5% | Aug 5, 2024 | Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially le... |
| CVE-2024-33034 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaimi... |
| CVE-2024-33028 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. |
| CVE-2024-33027 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corruptin... |
| CVE-2024-33026 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of ... |
| CVE-2024-33025 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |
| CVE-2024-33024 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the M... |
| CVE-2024-33023 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. |
| CVE-2024-33022 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption while allocating memory in HGSL driver. |
| CVE-2024-33021 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption while processing IOCTL call to set metainfo. |
| CVE-2024-33020 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while processing TID-to-link mapping IE elements. |
| CVE-2024-33019 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing the received TID-to-link mapping action frame. |
| CVE-2024-33018 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. |
| CVE-2024-33015 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is les... |
| CVE-2024-33014 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. |
| CVE-2024-33013 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
| CVE-2024-33012 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end ... |
| CVE-2024-33011 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
| CVE-2024-33010 | HIGH | 7.5 | 0.3% | Aug 5, 2024 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
| CVE-2024-23384 | HIGH | 8.4 | 0.1% | Aug 5, 2024 | Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker. |
| CVE-2024-23383 | HIGH | 7.8 | 0.1% | Aug 5, 2024 | Memory corruption when kernel driver attempts to trigger hardware fences. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now