2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37040 | HIGH | 8.1 | 0.4% | Jun 12, 2024 | CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a ... |
| CVE-2024-37039 | HIGH | 7.5 | 0.8% | Jun 12, 2024 | CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker s... |
| CVE-2024-37038 | HIGH | 8.8 | 0.4% | Jun 12, 2024 | CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the de... |
| CVE-2024-37037 | HIGH | 8.1 | 1.0% | Jun 12, 2024 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could a... |
| CVE-2024-37300 | HIGH | 8.1 | 0.4% | Jun 12, 2024 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub <... |
| CVE-2024-34065 | HIGH | 8.1 | 0.7% | Jun 12, 2024 | Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session to... |
| CVE-2024-28964 | HIGH | 7.8 | 0.4% | Jun 12, 2024 | Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A... |
| CVE-2024-36263 | HIGH | 8.1 | 1.0% | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vul... |
| CVE-2024-25949 | HIGH | 8.8 | 0.4% | Jun 12, 2024 | Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vuln... |
| CVE-2024-5211 | HIGH | 7.2 | 1.0% | Jun 12, 2024 | A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function,... |
| CVE-2024-4845 | HIGH | 8.8 | 0.5% | Jun 12, 2024 | The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all vers... |
| CVE-2024-5154 | HIGH | 8.1 | 1.2% | Jun 12, 2024 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory... |
| CVE-2024-3183 | HIGH | 8.1 | 2.1% | Jun 12, 2024 | A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This ... |
| CVE-2024-2698 | HIGH | 8.8 | 0.7% | Jun 12, 2024 | A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition... |
| CVE-2024-36856 | HIGH | 7.5 | 0.5% | Jun 12, 2024 | RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can... |
| CVE-2024-5543 | HIGH | 8.1 | 0.5% | Jun 12, 2024 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all ve... |
| CVE-2024-5847 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-5846 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-5845 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-5844 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of... |
| CVE-2024-5842 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to e... |
| CVE-2024-5841 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-5838 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory a... |
| CVE-2024-5837 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bou... |
| CVE-2024-5836 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a use... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now