2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-28739HIGH7.2An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the for...
CVE-2024-7502HIGH7.8A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attack...
CVE-2024-7000HIGH8.8Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage i...
CVE-2024-6998HIGH8.8Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user ...
CVE-2024-6997HIGH8.8Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage ...
CVE-2024-6994HIGH8.8Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit ...
CVE-2024-6991HIGH8.8Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-6989HIGH8.8Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap c...
CVE-2024-6988HIGH8.8Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially expl...
CVE-2024-6720HIGH8.8The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to m...
CVE-2024-23460HIGH7.8The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrar...
CVE-2024-23458HIGH7.8While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks,...
CVE-2024-23456HIGH7.5Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connec...
CVE-2024-7552HIGH8.8A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is t...
CVE-2024-41913HIGH8.8A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware fla...
CVE-2024-41226HIGH7.8A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary ...
CVE-2024-7530HIGH8.8Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
CVE-2024-7528HIGH8.8Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Fir...
CVE-2024-7527HIGH8.8Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox ...
CVE-2024-7525HIGH8.1It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and ...
CVE-2024-7523HIGH8.1A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into gr...
CVE-2024-7522HIGH8.8Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects...
CVE-2024-7521HIGH8.8Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, F...
CVE-2024-7520HIGH8.8A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulner...
CVE-2024-6358HIGH8.8Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now