2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32256HIGH8.1Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admi...
CVE-2024-32254HIGH8.8Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin...
CVE-2024-32086HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affect...
CVE-2024-21676Rejected reason: This CVE's publication may have been a false positive or a mistake. As a result, we have rejected this ...
CVE-2024-3874HIGH8.8A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the func...
CVE-2024-3873MEDIUM4.3A vulnerability was found in SMI SMI-EX-5414W up to 1.0.03. It has been classified as problematic. This affects an unkno...
CVE-2024-3865HIGH8.1Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-3864HIGH8.1Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c...
CVE-2024-3863CRITICAL9.8The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows ...
CVE-2024-3862MEDIUM5.3The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a...
CVE-2024-3861MEDIUM4If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and l...
CVE-2024-3860MEDIUM6.2An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently tra...
CVE-2024-3859MEDIUM5.9On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by...
CVE-2024-3858HIGH7.5It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F...
CVE-2024-3857HIGH7.8The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garba...
CVE-2024-3856HIGH8.8A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulne...
CVE-2024-3855MEDIUM6.5In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability ...
CVE-2024-3854HIGH8.8In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This ...
CVE-2024-3853HIGH7.5A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection st...
CVE-2024-3852HIGH7.5GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects...
CVE-2024-3302LOW3.7There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to cre...
CVE-2024-32027CRITICAL9.8Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetun...
CVE-2024-32026CRITICAL9.8Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_g...
CVE-2024-32025CRITICAL9.1Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_...
CVE-2024-32024MEDIUM6.5Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now