2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21308HIGH8.8SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21303HIGH8.8SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-20701HIGH8.8SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-27783HIGH8.8Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an ...
CVE-2024-23663HIGH8.8An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 a...
CVE-2024-6615HIGH8.8Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption a...
CVE-2024-6609HIGH8.8When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerabilit...
CVE-2024-6607HIGH8.8It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notificati...
CVE-2024-6606HIGH8.2Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerab...
CVE-2024-6605HIGH8.8Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerabi...
CVE-2024-6604HIGH7.5Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidenc...
CVE-2024-6603HIGH7.4In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading ...
CVE-2024-39697HIGH8.6phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumbe...
CVE-2024-38363HIGH8.5Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE v...
CVE-2024-37952HIGH8.8Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects...
CVE-2024-37520HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-37513HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allow...
CVE-2024-22271HIGH8.2In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to ...
CVE-2024-39888HIGH8.7A vulnerability has been identified in Mendix Encryption (All versions >= V10.0.0 < V10.0.2). Affected versions of the m...
CVE-2024-39874HIGH7.5A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ...
CVE-2024-39873HIGH7.5A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ...
CVE-2024-39870HIGH7.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications...
CVE-2024-39868HIGH7.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not p...
CVE-2024-39867HIGH7.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not p...
CVE-2024-39866HIGH8.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now