2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22058 | HIGH | 7.8 | 0.4% | May 31, 2024 | A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary... |
| CVE-2024-36120 | HIGH | 7.8 | 0.3% | May 31, 2024 | javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targetin... |
| CVE-2024-35142 | HIGH | 7.8 | 0.2% | May 31, 2024 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe... |
| CVE-2024-35140 | HIGH | 7.8 | 0.1% | May 31, 2024 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to imp... |
| CVE-2024-28736 | HIGH | 7.1 | 2.5% | May 31, 2024 | An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page ... |
| CVE-2024-5565 | HIGH | 8.1 | 15.0% | May 31, 2024 | The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt... |
| CVE-2024-5525 | HIGH | 8.8 | 0.4% | May 31, 2024 | Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a loca... |
| CVE-2024-5523 | HIGH | 8.8 | 0.4% | May 31, 2024 | SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated ... |
| CVE-2024-4469 | HIGH | 7.5 | 0.6% | May 31, 2024 | The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role... |
| CVE-2024-2793 | HIGH | 7.2 | 0.5% | May 31, 2024 | The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-37032 | HIGH | 8.8 | 89.6% | May 31, 2024 | Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,... |
| CVE-2024-5345 | HIGH | 8.8 | 0.7% | May 31, 2024 | The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up ... |
| CVE-2024-37017 | HIGH | 8.1 | 0.5% | May 31, 2024 | asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_Time... |
| CVE-2024-5499 | HIGH | 8.8 | 0.9% | May 30, 2024 | Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitra... |
| CVE-2024-5498 | HIGH | 8.8 | 0.6% | May 30, 2024 | Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exp... |
| CVE-2024-5497 | HIGH | 8.8 | 0.7% | May 30, 2024 | Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinc... |
| CVE-2024-5496 | HIGH | 8.8 | 0.8% | May 30, 2024 | Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary ... |
| CVE-2024-5495 | HIGH | 8.8 | 0.7% | May 30, 2024 | Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-5494 | HIGH | 8.8 | 0.7% | May 30, 2024 | Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-5493 | HIGH | 8.8 | 0.7% | May 30, 2024 | Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit... |
| CVE-2024-5271 | HIGH | 8.5 | 0.4% | May 30, 2024 | Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result i... |
| CVE-2024-35433 | HIGH | 8.1 | 0.5% | May 30, 2024 | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions ... |
| CVE-2024-2422 | HIGH | 8.8 | 0.5% | May 30, 2024 | LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions pri... |
| CVE-2024-35431 | HIGH | 7.5 | 1.0% | May 30, 2024 | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download... |
| CVE-2024-35428 | HIGH | 7.1 | 0.8% | May 30, 2024 | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete l... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now