2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33950MEDIUM5.9Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.
CVE-2024-33942MEDIUM4.3Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a throug...
CVE-2024-33938MEDIUM6.5Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects ...
CVE-2024-33878Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-33877HIGH8.8HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.
CVE-2024-33876MEDIUM5.7HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.
CVE-2024-33875MEDIUM5.7HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corr...
CVE-2024-33874CRITICAL9.8HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.
CVE-2024-33873HIGH8.8HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.
CVE-2024-33819MEDIUM4.6Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Quer...
CVE-2024-33818HIGH7.5Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID paramete...
CVE-2024-33774MEDIUM6.5A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authe...
CVE-2024-33773MEDIUM6.5A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authent...
CVE-2024-33772MEDIUM5.7A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticat...
CVE-2024-33771MEDIUM6.5A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authentica...
CVE-2024-33454MEDIUM6.5Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script t...
CVE-2024-33433MEDIUM4.8Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute a...
CVE-2024-33386Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-33263MEDIUM4QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.
CVE-2024-33250HIGH7.2An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a re...
CVE-2024-32999MEDIUM5.5Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect avail...
CVE-2024-32998MEDIUM5.5NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect ...
CVE-2024-32997MEDIUM4.7Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affe...
CVE-2024-32996MEDIUM5.5Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affe...
CVE-2024-32995MEDIUM5.5Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now