2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43106CRITICAL9.1A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Ex...
CVE-2024-42220CRITICAL9.1A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverag...
CVE-2024-42004CRITICAL9.8A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially...
CVE-2024-41165CRITICAL9.1A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor...
CVE-2024-41159HIGH7.1A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage ...
CVE-2024-41145CRITICAL9.8A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.27...
CVE-2024-41138CRITICAL9.8A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work ...
CVE-2024-39804CRITICAL9.1A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can levera...
CVE-2024-37649MEDIUM4.6Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proxi...
CVE-2024-55505HIGH8.8An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-vie...
CVE-2024-55232MEDIUM5.4An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows un...
CVE-2024-55231MEDIUM4.3An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unau...
CVE-2024-12695HIGH8.8Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code i...
CVE-2024-12694HIGH8.8Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit ...
CVE-2024-12693HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrar...
CVE-2024-12692HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-56145CRITICAL9.8Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected ...
CVE-2024-56140MEDIUM6.5Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware a...
CVE-2024-45338MEDIUM5.3An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, r...
CVE-2024-12686HIGH7.2A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacke...
CVE-2024-53271HIGH7.1Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle...
CVE-2024-53270HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to...
CVE-2024-53269HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then t...
CVE-2024-52593MEDIUM5.3Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService...
CVE-2024-52592MEDIUM5.3Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now