2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5830HIGH8.8Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memor...
CVE-2024-5646MEDIUM5.4The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute with...
CVE-2024-4669MEDIUM5.4The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, U...
CVE-2024-33606HIGH8.8An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing me...
CVE-2024-28877HIGH8.8MicroDicom DICOM Viewer is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary...
CVE-2024-37301HIGH7.2Document Merge Service is a document template merge service providing an API to manage templates and merge them with giv...
CVE-2024-36702HIGH7.4libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder...
CVE-2024-35213CRITICAL9An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an...
CVE-2024-34406MEDIUM5.3Improper exception handling in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to cause ...
CVE-2024-34405CRITICAL9.1Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to laun...
CVE-2024-28024MEDIUM4.1A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource th...
CVE-2024-28022MEDIUM6.5A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary...
CVE-2024-28020HIGH8A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malic...
CVE-2024-5851MEDIUM5.3A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the ...
CVE-2024-4190HIGH8.4Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities ...
CVE-2024-36821MEDIUM6.8Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest ...
CVE-2024-37325HIGH8.1Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
CVE-2024-37293HIGH7.8The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and region...
CVE-2024-35265HIGH7Windows Perception Service Elevation of Privilege Vulnerability
CVE-2024-35263MEDIUM5.7Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-35255MEDIUM5.5Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-35254HIGH7.1Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2024-35253MEDIUM4.4Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2024-35252HIGH7.5Azure Storage Movement Client Library Denial of Service Vulnerability
CVE-2024-35250HIGH7.8Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now