2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-20483HIGH7.2Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s...
CVE-2024-20406HIGH7.4A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci...
CVE-2024-20398HIGH7.8A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write fi...
CVE-2024-20381HIGH8.8A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is use...
CVE-2024-20317HIGH7.4A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergen...
CVE-2024-20304HIGH7.5A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthen...
CVE-2024-5760HIGH7.8The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creatio...
CVE-2024-45026HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corru...
CVE-2024-45023HIGH7.1In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array wi...
CVE-2024-39378HIGH7.8Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in a...
CVE-2024-8306HIGH7.8CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit...
CVE-2024-8642HIGH8.1In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApi...
CVE-2024-8639HIGH8.8Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially ...
CVE-2024-8638HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object co...
CVE-2024-8637HIGH8.8Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentia...
CVE-2024-8636HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit h...
CVE-2024-7609HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTE...
CVE-2024-45788HIGH7.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API e...
CVE-2024-45327HIGH7.5An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 t...
CVE-2024-7626HIGH8.1The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar...
CVE-2024-43690HIGH8Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allo...
CVE-2024-21529HIGH8.8Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user ...
CVE-2024-8253HIGH8.8The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to ...
CVE-2024-40662HIGH7.8In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This co...
CVE-2024-40658HIGH7.8In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now