2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-22058HIGH7.8A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary...
CVE-2024-36120HIGH7.8javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targetin...
CVE-2024-35142HIGH7.8IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe...
CVE-2024-35140HIGH7.8IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to imp...
CVE-2024-28736HIGH7.1An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page ...
CVE-2024-5565HIGH8.1The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt...
CVE-2024-5525HIGH8.8Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a loca...
CVE-2024-5523HIGH8.8SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated ...
CVE-2024-4469HIGH7.5The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role...
CVE-2024-2793HIGH7.2The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-37032HIGH8.8Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,...
CVE-2024-5345HIGH8.8The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up ...
CVE-2024-37017HIGH8.1asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_Time...
CVE-2024-5499HIGH8.8Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitra...
CVE-2024-5498HIGH8.8Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exp...
CVE-2024-5497HIGH8.8Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinc...
CVE-2024-5496HIGH8.8Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary ...
CVE-2024-5495HIGH8.8Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co...
CVE-2024-5494HIGH8.8Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co...
CVE-2024-5493HIGH8.8Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit...
CVE-2024-5271HIGH8.5Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result i...
CVE-2024-35433HIGH8.1ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions ...
CVE-2024-2422HIGH8.8LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions pri...
CVE-2024-35431HIGH7.5ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download...
CVE-2024-35428HIGH7.1ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now