2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37040HIGH8.1CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a ...
CVE-2024-37039HIGH7.5CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker s...
CVE-2024-37038HIGH8.8CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the de...
CVE-2024-37037HIGH8.1CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could a...
CVE-2024-37300HIGH8.1OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub <...
CVE-2024-34065HIGH8.1Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session to...
CVE-2024-28964HIGH7.8Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A...
CVE-2024-36263HIGH8.1** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vul...
CVE-2024-25949HIGH8.8Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vuln...
CVE-2024-5211HIGH7.2A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function,...
CVE-2024-4845HIGH8.8The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all vers...
CVE-2024-5154HIGH8.1A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory...
CVE-2024-3183HIGH8.1A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This ...
CVE-2024-2698HIGH8.8A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition...
CVE-2024-36856HIGH7.5RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can...
CVE-2024-5543HIGH8.1The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all ve...
CVE-2024-5847HIGH8.8Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap c...
CVE-2024-5846HIGH8.8Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap c...
CVE-2024-5845HIGH8.8Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap co...
CVE-2024-5844HIGH8.8Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of...
CVE-2024-5842HIGH8.8Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to e...
CVE-2024-5841HIGH8.8Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-5838HIGH8.8Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory a...
CVE-2024-5837HIGH8.8Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bou...
CVE-2024-5836HIGH8.8Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a use...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now