2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37002HIGH7.8A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitiali...
CVE-2024-37001HIGH7.8A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-...
CVE-2024-37000HIGH7.8A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corrupti...
CVE-2024-23149HIGH7.8A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound...
CVE-2024-23148HIGH7.8A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory cor...
CVE-2024-23147HIGH7.8A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applica...
CVE-2024-23146HIGH7.8A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through through Autodesk AutoCAD, may force an Out-o...
CVE-2024-23145HIGH7.8A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Re...
CVE-2024-23144HIGH7.8A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an...
CVE-2024-23143HIGH7.8A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk appli...
CVE-2024-23142HIGH7.8A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll...
CVE-2024-23141HIGH7.8A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This ...
CVE-2024-23140HIGH7.8A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, ca...
CVE-2024-36683HIGH7.3SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho...
CVE-2024-34992HIGH8.8SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4....
CVE-2024-6293HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co...
CVE-2024-6292HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co...
CVE-2024-6291HIGH8.8Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit ...
CVE-2024-6290HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co...
CVE-2024-36682HIGH7.5In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all ema...
CVE-2024-34991HIGH7.5In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credi...
CVE-2024-37677HIGH7.5An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacke...
CVE-2024-38373HIGH8.1FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a b...
CVE-2024-6287HIGH7.8Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whet...
CVE-2024-33687HIGH7.5Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now