2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32256 | HIGH | 8.1 | 0.7% | Apr 16, 2024 | Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admi... |
| CVE-2024-32254 | HIGH | 8.8 | 0.8% | Apr 16, 2024 | Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin... |
| CVE-2024-32086 | HIGH | 7.5 | 0.5% | Apr 16, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affect... |
| CVE-2024-21676 | — | — | — | Apr 16, 2024 | Rejected reason: This CVE's publication may have been a false positive or a mistake. As a result, we have rejected this ... |
| CVE-2024-3874 | HIGH | 8.8 | 1.3% | Apr 16, 2024 | A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the func... |
| CVE-2024-3873 | MEDIUM | 4.3 | 0.3% | Apr 16, 2024 | A vulnerability was found in SMI SMI-EX-5414W up to 1.0.03. It has been classified as problematic. This affects an unkno... |
| CVE-2024-3865 | HIGH | 8.1 | 0.5% | Apr 16, 2024 | Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-3864 | HIGH | 8.1 | 0.8% | Apr 16, 2024 | Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c... |
| CVE-2024-3863 | CRITICAL | 9.8 | 0.8% | Apr 16, 2024 | The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows ... |
| CVE-2024-3862 | MEDIUM | 5.3 | 0.4% | Apr 16, 2024 | The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a... |
| CVE-2024-3861 | MEDIUM | 4 | 0.2% | Apr 16, 2024 | If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and l... |
| CVE-2024-3860 | MEDIUM | 6.2 | 0.2% | Apr 16, 2024 | An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently tra... |
| CVE-2024-3859 | MEDIUM | 5.9 | 0.7% | Apr 16, 2024 | On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by... |
| CVE-2024-3858 | HIGH | 7.5 | 0.6% | Apr 16, 2024 | It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F... |
| CVE-2024-3857 | HIGH | 7.8 | 0.2% | Apr 16, 2024 | The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garba... |
| CVE-2024-3856 | HIGH | 8.8 | 0.6% | Apr 16, 2024 | A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulne... |
| CVE-2024-3855 | MEDIUM | 6.5 | 0.4% | Apr 16, 2024 | In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability ... |
| CVE-2024-3854 | HIGH | 8.8 | 0.7% | Apr 16, 2024 | In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This ... |
| CVE-2024-3853 | HIGH | 7.5 | 0.4% | Apr 16, 2024 | A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection st... |
| CVE-2024-3852 | HIGH | 7.5 | 0.6% | Apr 16, 2024 | GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects... |
| CVE-2024-3302 | LOW | 3.7 | 0.8% | Apr 16, 2024 | There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to cre... |
| CVE-2024-32027 | CRITICAL | 9.8 | 3.0% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetun... |
| CVE-2024-32026 | CRITICAL | 9.8 | 3.0% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_g... |
| CVE-2024-32025 | CRITICAL | 9.1 | 2.5% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_... |
| CVE-2024-32024 | MEDIUM | 6.5 | 0.7% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now