2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56317HIGH7.5In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries ...
CVE-2024-56116HIGH8.8A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator ...
CVE-2024-56115MEDIUM6.1A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It ...
CVE-2024-55506HIGH8.8An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to ex...
CVE-2024-55461CRITICAL9.8SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
CVE-2024-55239MEDIUM5.4A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar...
CVE-2024-53580HIGH7.5iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
CVE-2024-43106CRITICAL9.1A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Ex...
CVE-2024-42220CRITICAL9.1A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverag...
CVE-2024-42004CRITICAL9.8A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially...
CVE-2024-41165CRITICAL9.1A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor...
CVE-2024-41159HIGH7.1A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage ...
CVE-2024-41145CRITICAL9.8A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.27...
CVE-2024-41138CRITICAL9.8A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work ...
CVE-2024-39804CRITICAL9.1A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can levera...
CVE-2024-37649MEDIUM4.6Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proxi...
CVE-2024-55505HIGH8.8An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-vie...
CVE-2024-55232MEDIUM5.4An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows un...
CVE-2024-55231MEDIUM4.3An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unau...
CVE-2024-12695HIGH8.8Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code i...
CVE-2024-12694HIGH8.8Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit ...
CVE-2024-12693HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrar...
CVE-2024-12692HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-56145CRITICAL9.8Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected ...
CVE-2024-56140MEDIUM6.5Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now