2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53675HIGH7.5An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in...
CVE-2024-53674HIGH7.5An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in...
CVE-2024-11622HIGH7.5An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in...
CVE-2024-8676HIGH7.4A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a...
CVE-2024-49053HIGH7.6Microsoft Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-8237HIGH7.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5...
CVE-2024-8177HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 pr...
CVE-2024-8114HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17....
CVE-2024-52008HIGH8.8Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password...
CVE-2024-32965HIGH8.6Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera...
CVE-2024-11828HIGH7.5A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17....
CVE-2024-11669HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b...
CVE-2024-53555HIGH8.8A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil...
CVE-2024-11407HIGH7.5There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled ...
CVE-2024-52336HIGH7.8A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call...
CVE-2024-36463HIGH8.8The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal...
CVE-2024-9461HIGH7.2The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo...
CVE-2024-11702HIGH7.5Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored da...
CVE-2024-11700HIGH8.1Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to use...
CVE-2024-11699HIGH8.8Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence ...
CVE-2024-11697HIGH8.8When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"...
CVE-2024-11691HIGH8.8Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corrupti...
CVE-2024-51569HIGH7.5Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l...
CVE-2024-38831HIGH7.8VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative...
CVE-2024-38830HIGH7.8VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now