2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2932 | HIGH | 7.5 | 0.6% | Mar 27, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unkno... |
| CVE-2024-2206 | MEDIUM | 6.5 | 0.4% | Mar 27, 2024 | An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/prox... |
| CVE-2024-2930 | CRITICAL | 9.8 | 1.2% | Mar 27, 2024 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this v... |
| CVE-2024-2209 | MEDIUM | 6.3 | 0.2% | Mar 27, 2024 | A user with administrative privileges can create a compromised dll file of the same name as the original dll within the ... |
| CVE-2024-2927 | CRITICAL | 9.8 | 0.8% | Mar 26, 2024 | A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown f... |
| CVE-2024-2917 | CRITICAL | 9.8 | 0.8% | Mar 26, 2024 | A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by... |
| CVE-2024-2916 | MEDIUM | 6.5 | 0.6% | Mar 26, 2024 | A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected ... |
| CVE-2024-26577 | HIGH | 7.5 | 0.6% | Mar 26, 2024 | VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet co... |
| CVE-2024-25138 | MEDIUM | 6.5 | 0.4% | Mar 26, 2024 | In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device. |
| CVE-2024-25137 | MEDIUM | 4.3 | 0.4% | Mar 26, 2024 | In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limi... |
| CVE-2024-25136 | HIGH | 7.5 | 0.6% | Mar 26, 2024 | There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL witho... |
| CVE-2024-2971 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the inp... |
| CVE-2024-2911 | MEDIUM | 6.9 | 0.3% | Mar 26, 2024 | A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknow... |
| CVE-2024-2910 | HIGH | 8.8 | 3.7% | Mar 26, 2024 | A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this is... |
| CVE-2024-2909 | HIGH | 8.8 | 4.0% | Mar 26, 2024 | A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is th... |
| CVE-2024-2903 | HIGH | 8.8 | 1.8% | Mar 26, 2024 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetPare... |
| CVE-2024-2887 | HIGH | 7.7 | 19.9% | Mar 26, 2024 | Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary cod... |
| CVE-2024-2886 | HIGH | 7.5 | 2.1% | Mar 26, 2024 | Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/... |
| CVE-2024-2885 | HIGH | 8.8 | 1.2% | Mar 26, 2024 | Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-2883 | HIGH | 8.8 | 3.3% | Mar 26, 2024 | Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-28551 | HIGH | 7.5 | 0.8% | Mar 26, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function. |
| CVE-2024-28545 | CRITICAL | 9.8 | 2.3% | Mar 26, 2024 | Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload func... |
| CVE-2024-27521 | HIGH | 8 | 1.5% | Mar 26, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vuln... |
| CVE-2024-26303 | MEDIUM | 4.9 | 0.5% | Mar 26, 2024 | Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon |
| CVE-2024-25421 | CRITICAL | 9.8 | 1.7% | Mar 26, 2024 | An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CAC... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now