2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42776HIGH7.2Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
CVE-2024-42774HIGH7.5An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0,...
CVE-2024-42772HIGH7.5An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which...
CVE-2024-42490HIGH7.5authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica...
CVE-2024-36444HIGH8.1cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device...
CVE-2024-36442HIGH8.8cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar...
CVE-2024-36443HIGH7.6Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonym...
CVE-2024-39745HIGH7.5IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that ...
CVE-2024-8071HIGH7.2Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can...
CVE-2024-40886HIGH8.8Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the...
CVE-2024-7384HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2024-39576HIGH8.8Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low pri...
CVE-2024-43033HIGH8.8JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via...
CVE-2024-7980HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7979HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7977HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7974HIGH8.8Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially ...
CVE-2024-7973HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bo...
CVE-2024-7972HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perf...
CVE-2024-7969HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-7968HIGH8.8Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user ...
CVE-2024-7967HIGH8.8Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit h...
CVE-2024-7966HIGH8.8Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromise...
CVE-2024-7965HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl...
CVE-2024-7964HIGH8.8Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now