2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28739 | HIGH | 7.2 | 17.7% | Aug 6, 2024 | An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the for... |
| CVE-2024-7502 | HIGH | 7.8 | 0.4% | Aug 6, 2024 | A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attack... |
| CVE-2024-7000 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage i... |
| CVE-2024-6998 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user ... |
| CVE-2024-6997 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage ... |
| CVE-2024-6994 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit ... |
| CVE-2024-6991 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-6989 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-6988 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially expl... |
| CVE-2024-6720 | HIGH | 8.8 | 0.2% | Aug 6, 2024 | The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to m... |
| CVE-2024-23460 | HIGH | 7.8 | 0.1% | Aug 6, 2024 | The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrar... |
| CVE-2024-23458 | HIGH | 7.8 | 0.1% | Aug 6, 2024 | While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks,... |
| CVE-2024-23456 | HIGH | 7.5 | 0.2% | Aug 6, 2024 | Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connec... |
| CVE-2024-7552 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is t... |
| CVE-2024-41913 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware fla... |
| CVE-2024-41226 | HIGH | 7.8 | 0.5% | Aug 6, 2024 | A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary ... |
| CVE-2024-7530 | HIGH | 8.8 | 0.4% | Aug 6, 2024 | Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129. |
| CVE-2024-7528 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Fir... |
| CVE-2024-7527 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox ... |
| CVE-2024-7525 | HIGH | 8.1 | 0.6% | Aug 6, 2024 | It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and ... |
| CVE-2024-7523 | HIGH | 8.1 | 0.3% | Aug 6, 2024 | A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into gr... |
| CVE-2024-7522 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects... |
| CVE-2024-7521 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, F... |
| CVE-2024-7520 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulner... |
| CVE-2024-6358 | HIGH | 8.8 | 0.3% | Aug 6, 2024 | Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now