2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21146HIGH8.1Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported ver...
CVE-2024-21141HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2024-21136HIGH8.6Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported...
CVE-2024-6778HIGH7.5Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a maliciou...
CVE-2024-6776HIGH8.8Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap c...
CVE-2024-6775HIGH8.8Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user t...
CVE-2024-6774HIGH8.8Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user...
CVE-2024-6773HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exp...
CVE-2024-6772HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of ...
CVE-2024-21687HIGH8.1This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and ...
CVE-2024-21686HIGH8.7This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This ...
CVE-2024-6492HIGH7.4Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14....
CVE-2024-40516HIGH8.8An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary ...
CVE-2024-33181HIGH8.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parame...
CVE-2024-6089HIGH7.5An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent...
CVE-2024-40322HIGH8.8An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
CVE-2024-6655HIGH7A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK ap...
CVE-2024-32861HIGH7.8Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission...
CVE-2024-6435HIGH8.8A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privi...
CVE-2024-6457HIGH7.5The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection ...
CVE-2024-40631HIGH8.1Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlPars...
CVE-2024-36438HIGH7.3eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check...
CVE-2024-36434HIGH7.5An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmw...
CVE-2024-36433HIGH7.5An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with...
CVE-2024-36432HIGH7.5An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN mo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now