2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2932HIGH7.5A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unkno...
CVE-2024-2206MEDIUM6.5An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/prox...
CVE-2024-2930CRITICAL9.8A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this v...
CVE-2024-2209MEDIUM6.3A user with administrative privileges can create a compromised dll file of the same name as the original dll within the ...
CVE-2024-2927CRITICAL9.8A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown f...
CVE-2024-2917CRITICAL9.8A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by...
CVE-2024-2916MEDIUM6.5A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected ...
CVE-2024-26577HIGH7.5VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet co...
CVE-2024-25138MEDIUM6.5 In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.
CVE-2024-25137MEDIUM4.3 In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limi...
CVE-2024-25136HIGH7.5 There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL witho...
CVE-2024-2971MEDIUM5.5Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the inp...
CVE-2024-2911MEDIUM6.9A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknow...
CVE-2024-2910HIGH8.8A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this is...
CVE-2024-2909HIGH8.8A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is th...
CVE-2024-2903HIGH8.8A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetPare...
CVE-2024-2887HIGH7.7Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary cod...
CVE-2024-2886HIGH7.5Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/...
CVE-2024-2885HIGH8.8Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-2883HIGH8.8Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap co...
CVE-2024-28551HIGH7.5Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.
CVE-2024-28545CRITICAL9.8Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload func...
CVE-2024-27521HIGH8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vuln...
CVE-2024-26303MEDIUM4.9Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon
CVE-2024-25421CRITICAL9.8An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CAC...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now