2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38991 | HIGH | 8.8 | 0.8% | Jul 1, 2024 | akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability al... |
| CVE-2024-38990 | MEDIUM | 6.3 | 0.5% | Jul 1, 2024 | Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability ... |
| CVE-2024-38987 | MEDIUM | 6.3 | 0.5% | Jul 1, 2024 | aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability ... |
| CVE-2024-39430 | MEDIUM | 6.2 | 0.1% | Jul 1, 2024 | In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-39429 | MEDIUM | 6.2 | 0.1% | Jul 1, 2024 | In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-39428 | MEDIUM | 4.4 | 0.1% | Jul 1, 2024 | In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-39427 | MEDIUM | 4.4 | 0.1% | Jul 1, 2024 | In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia... |
| CVE-2024-0153 | HIGH | 7.8 | 0.2% | Jul 1, 2024 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, A... |
| CVE-2024-6130 | MEDIUM | 4.8 | 0.4% | Jul 1, 2024 | The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-4934 | MEDIUM | 5.5 | 0.4% | Jul 1, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields bef... |
| CVE-2024-3123 | HIGH | 7.2 | 0.6% | Jul 1, 2024 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attac... |
| CVE-2024-3122 | MEDIUM | 4.9 | 0.6% | Jul 1, 2024 | CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remo... |
| CVE-2024-38480 | MEDIUM | 4 | 0.2% | Jul 1, 2024 | "Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may ... |
| CVE-2024-20081 | MEDIUM | 6.7 | 0.2% | Jul 1, 2024 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esca... |
| CVE-2024-20080 | CRITICAL | 9.8 | 0.3% | Jul 1, 2024 | In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to ... |
| CVE-2024-20079 | MEDIUM | 6.7 | 0.2% | Jul 1, 2024 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esca... |
| CVE-2024-20078 | CRITICAL | 9.8 | 0.3% | Jul 1, 2024 | In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege... |
| CVE-2024-20077 | HIGH | 7.5 | 0.8% | Jul 1, 2024 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ... |
| CVE-2024-20076 | HIGH | 7.5 | 0.8% | Jul 1, 2024 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ... |
| CVE-2024-6419 | CRITICAL | 9.8 | 0.6% | Jul 1, 2024 | A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affec... |
| CVE-2024-6418 | MEDIUM | 5.3 | 0.5% | Jun 30, 2024 | A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unk... |
| CVE-2024-6417 | HIGH | 7.5 | 0.5% | Jun 30, 2024 | A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by... |
| CVE-2024-6416 | CRITICAL | 9.8 | 0.5% | Jun 30, 2024 | A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown... |
| CVE-2024-34703 | HIGH | 7.5 | 0.5% | Jun 30, 2024 | Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o... |
| CVE-2024-28794 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now