2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45442HIGH7.5Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of ...
CVE-2024-45441HIGH7.5Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will...
CVE-2024-42039HIGH7.5Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2024-41716HIGH8.1Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exp...
CVE-2024-8362HIGH8.8Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit hea...
CVE-2024-7970HIGH8.8Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap...
CVE-2024-45394HIGH7.8Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption...
CVE-2024-45391HIGH7.5Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prio...
CVE-2024-41436HIGH7.5ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
CVE-2024-41435HIGH7.5YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
CVE-2024-42902HIGH8.8An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via ...
CVE-2024-38456HIGH7.8HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and fo...
CVE-2024-6119HIGH7.5Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may atte...
CVE-2024-42991HIGH8.1MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-8383HIGH7.5Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that...
CVE-2024-8382HIGH8.8Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for th...
CVE-2024-6232HIGH7.5There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking...
CVE-2024-6473HIGH7.8Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-45588HIGH8.1This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A...
CVE-2024-8374HIGH7.8UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/p...
CVE-2024-45587HIGH8.8This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A...
CVE-2024-45586HIGH8.8This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Tradi...
CVE-2024-3655HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2024-38811HIGH7.8VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var...
CVE-2024-7203HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now