2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-0645HIGH7.8Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code v...
CVE-2024-22409HIGH8.8DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group ...
CVE-2024-22408HIGH8.1Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application d...
CVE-2024-21670HIGH8.1Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures i...
CVE-2024-20952HIGH7.4Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2024-20932HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2024-20924HIGH7.6Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a...
CVE-2024-20918HIGH7.4Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2024-20916HIGH8.3Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana...
CVE-2024-0519HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially expl...
CVE-2024-0518HIGH8.8Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-0517HIGH8.8Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap...
CVE-2024-0507HIGH8.8An attacker with access to a Management Console user account with the editor role could escalate privileges through a co...
CVE-2024-23347HIGH7.8Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file ...
CVE-2024-22628HIGH7.2Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&dat...
CVE-2024-22627HIGH7.2Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distrib...
CVE-2024-22626HIGH7.2Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retaile...
CVE-2024-22625HIGH7.2Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_categor...
CVE-2024-0582HIGH7.8A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IOR...
CVE-2024-0567HIGH7.5A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed tr...
CVE-2024-0553HIGH7.5A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ fro...
CVE-2024-0555HIGH8A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated use...
CVE-2024-21674HIGH7.5This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center ...
CVE-2024-21673HIGH8.8This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center...
CVE-2024-21672HIGH8.8This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now