2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38991HIGH8.8akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability al...
CVE-2024-38990MEDIUM6.3Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability ...
CVE-2024-38987MEDIUM6.3aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability ...
CVE-2024-39430MEDIUM6.2In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia...
CVE-2024-39429MEDIUM6.2In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia...
CVE-2024-39428MEDIUM4.4In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia...
CVE-2024-39427MEDIUM4.4In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia...
CVE-2024-0153HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, A...
CVE-2024-6130MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could ...
CVE-2024-4934MEDIUM5.5The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields bef...
CVE-2024-3123HIGH7.2CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attac...
CVE-2024-3122MEDIUM4.9CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remo...
CVE-2024-38480MEDIUM4"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may ...
CVE-2024-20081MEDIUM6.7In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esca...
CVE-2024-20080CRITICAL9.8In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to ...
CVE-2024-20079MEDIUM6.7In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esca...
CVE-2024-20078CRITICAL9.8In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege...
CVE-2024-20077HIGH7.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ...
CVE-2024-20076HIGH7.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ...
CVE-2024-6419CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affec...
CVE-2024-6418MEDIUM5.3A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unk...
CVE-2024-6417HIGH7.5A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by...
CVE-2024-6416CRITICAL9.8A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown...
CVE-2024-34703HIGH7.5Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o...
CVE-2024-28794MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now