2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25274CRITICAL9.8An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to exe...
CVE-2024-23809CRITICAL9.8A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig...
CVE-2024-23606CRITICAL9.8An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 ...
CVE-2024-23313CRITICAL9.8An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 an...
CVE-2024-23310CRITICAL9.8A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Ma...
CVE-2024-23305CRITICAL9.8An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbios...
CVE-2024-22097CRITICAL9.8A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Maste...
CVE-2024-21812CRITICAL9.8An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and...
CVE-2024-21795CRITICAL9.8A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5....
CVE-2024-23114CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vul...
CVE-2024-22824CRITICAL9.8An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadC...
CVE-2024-22369HIGH7.8Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0...
CVE-2024-1156HIGH7.8Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ...
CVE-2024-1155HIGH7.8Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authentic...
CVE-2024-26270MEDIUM5.3The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 u...
CVE-2024-26268MEDIUM5.3User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP...
CVE-2024-25199HIGH8.1Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 ...
CVE-2024-25198CRITICAL9.1Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robo...
CVE-2024-25197MEDIUM6.5Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dere...
CVE-2024-25196LOW3.3Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow v...
CVE-2024-1557HIGH8.1Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-1556MEDIUM6.5The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and und...
CVE-2024-1555HIGH8.3When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulne...
CVE-2024-1554CRITICAL9.8The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional header...
CVE-2024-1553HIGH8.1Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now