2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21678HIGH8.5This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XS...
CVE-2024-22369HIGH7.8Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0...
CVE-2024-1156HIGH7.8Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ...
CVE-2024-1155HIGH7.8Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authentic...
CVE-2024-25199HIGH8.1Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 ...
CVE-2024-1557HIGH8.1Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-1555HIGH8.3When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulne...
CVE-2024-1553HIGH8.1Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence ...
CVE-2024-1552HIGH7.5Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This...
CVE-2024-1546HIGH7.5When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in a...
CVE-2024-26581HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval elemen...
CVE-2024-25607HIGH7.5The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupporte...
CVE-2024-25606HIGH8.7XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before up...
CVE-2024-1608HIGH7.5In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead...
CVE-2024-22234HIGH7.4In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to bro...
CVE-2024-22019HIGH7.5A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encodin...
CVE-2024-21892HIGH7.8On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the pro...
CVE-2024-21891HIGH8.8Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be ov...
CVE-2024-1648HIGH7.5electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible beca...
CVE-2024-1647HIGH7.5Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because...
CVE-2024-1644HIGH8.8Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LF...
CVE-2024-1297HIGH7.2Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vu...
CVE-2024-26134HIGH7.5cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format...
CVE-2024-1635HIGH7.5A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protoco...
CVE-2024-25636HIGH8.8Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now