2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39071CRITICAL9.8Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
CVE-2024-39031MEDIUM5.4In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, ...
CVE-2024-38959MEDIUM6.1Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attack...
CVE-2024-37865MEDIUM5.9An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive informati...
CVE-2024-37829HIGH8.8An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafte...
CVE-2024-34726HIGH7.8In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This co...
CVE-2024-34725HIGH7In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi...
CVE-2024-34724HIGH7In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead...
CVE-2024-34723HIGH7.8In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from back...
CVE-2024-34722HIGH8.8In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect imp...
CVE-2024-34721MEDIUM5.5In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to imprope...
CVE-2024-34720HIGH7.8In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, ...
CVE-2024-31339HIGH7.8In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lea...
CVE-2024-31335HIGH7.8In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in th...
CVE-2024-31334HIGH7.8In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error ...
CVE-2024-31332HIGH7.8In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing ...
CVE-2024-31331HIGH7.3In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic ...
CVE-2024-31327HIGH7In multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race condition. This could...
CVE-2024-31326HIGH7.8In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic erro...
CVE-2024-31325HIGH7.8In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This...
CVE-2024-31324HIGH7.3In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity i...
CVE-2024-31323HIGH7.8In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjack...
CVE-2024-31322HIGH7.8In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Se...
CVE-2024-31320HIGH7.8In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association withou...
CVE-2024-31319HIGH7.8In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user da...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now