2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27915HIGH8.1Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to page...
CVE-2024-2176HIGH8.8Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap c...
CVE-2024-2174HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exp...
CVE-2024-2173HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of b...
CVE-2024-27303HIGH7.3electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Wind...
CVE-2024-27289HIGH8.1pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the followin...
CVE-2024-27287HIGH8.7ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior t...
CVE-2024-25111HIGH7.5Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of ...
CVE-2024-24766HIGH7.5CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ...
CVE-2024-24761HIGH7.5Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to ...
CVE-2024-2216HIGH8.8A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers wit...
CVE-2024-28160HIGH8.8Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored ...
CVE-2024-28157HIGH8Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-si...
CVE-2024-20338HIGH7.3A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, l...
CVE-2024-20337HIGH8.2A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacke...
CVE-2024-2005HIGH8 In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation....
CVE-2024-25102HIGH7.8This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user...
CVE-2024-1224HIGH7.1This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user logi...
CVE-2024-26625HIGH7.8In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot rep...
CVE-2024-1220HIGH7.5A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and pri...
CVE-2024-25817HIGH7.8Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .gi...
CVE-2024-22889HIGH7.5Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the webs...
CVE-2024-27765HIGH7.5Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information vi...
CVE-2024-24786HIGH7.5The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condit...
CVE-2024-24784HIGH7.5The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now