2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5498HIGH8.8Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exp...
CVE-2024-5497HIGH8.8Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinc...
CVE-2024-5496HIGH8.8Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary ...
CVE-2024-5495HIGH8.8Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co...
CVE-2024-5494HIGH8.8Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co...
CVE-2024-5493HIGH8.8Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit...
CVE-2024-36119LOW1.8Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the ...
CVE-2024-1298MEDIUM6EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 ...
CVE-2024-5271HIGH8.5Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result i...
CVE-2024-4842Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: Not a vulnerability
CVE-2024-35189MEDIUM6.5Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `Conne...
CVE-2024-34171CRITICAL9.8Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute ...
CVE-2024-32877MEDIUM4.7Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a...
CVE-2024-35228MEDIUM5.5Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in th...
CVE-2024-35469CRITICAL9.8A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to e...
CVE-2024-35468MEDIUM5.4A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers ...
CVE-2024-35433HIGH8.1ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions ...
CVE-2024-2422HIGH8.8LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions pri...
CVE-2024-2421CRITICAL9.8LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions p...
CVE-2024-2420CRITICAL9.8LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions pr...
CVE-2024-5537Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-36118MEDIUM4.3MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions ca...
CVE-2024-35431HIGH7.5ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download...
CVE-2024-35429MEDIUM6.5ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
CVE-2024-35428HIGH7.1ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now