2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-29192HIGH8.8gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/...
CVE-2024-27268HIGH7.5IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sendi...
CVE-2024-25699HIGH8.5There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS version...
CVE-2024-25695HIGH7.2There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, a...
CVE-2024-30263HIGH7.7macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF a...
CVE-2024-3299HIGH7.8Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedur...
CVE-2024-3298HIGH7.8Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOL...
CVE-2024-30250HIGH7.5Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy he...
CVE-2024-28871HIGH7.5LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malfor...
CVE-2024-27919HIGH7.5Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol sta...
CVE-2024-22189HIGH7.5quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run ...
CVE-2024-31082HIGH7.3A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This is...
CVE-2024-31081HIGH7.3A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This iss...
CVE-2024-31080HIGH7.3A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This iss...
CVE-2024-2759HIGH7.5Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates...
CVE-2024-2700HIGH7A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus n...
CVE-2024-27575HIGH7.5INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path ...
CVE-2024-26808HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_chain_filter: handle NETDEV_UNREGIST...
CVE-2024-26804HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth ...
CVE-2024-26800HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryptio...
CVE-2024-26799HIGH7In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix uninitialized pointer dmactl In th...
CVE-2024-26797HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent potential buffer overflow ...
CVE-2024-26793HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_n...
CVE-2024-26792HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of anonymous device after sn...
CVE-2024-26791HIGH7.1In the Linux kernel, the following vulnerability has been resolved: btrfs: dev-replace: properly validate device names ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now