2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0645 | HIGH | 7.8 | 0.2% | Jan 17, 2024 | Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code v... |
| CVE-2024-22409 | HIGH | 8.8 | 0.7% | Jan 16, 2024 | DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group ... |
| CVE-2024-22408 | HIGH | 8.1 | 0.4% | Jan 16, 2024 | Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application d... |
| CVE-2024-21670 | HIGH | 8.1 | 0.3% | Jan 16, 2024 | Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures i... |
| CVE-2024-20952 | HIGH | 7.4 | 0.9% | Jan 16, 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2024-20932 | HIGH | 7.5 | 0.8% | Jan 16, 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2024-20924 | HIGH | 7.6 | 0.4% | Jan 16, 2024 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a... |
| CVE-2024-20918 | HIGH | 7.4 | 0.9% | Jan 16, 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2024-20916 | HIGH | 8.3 | 0.3% | Jan 16, 2024 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana... |
| CVE-2024-0519 | HIGH | 8.8 | 3.8% | Jan 16, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially expl... |
| CVE-2024-0518 | HIGH | 8.8 | 0.9% | Jan 16, 2024 | Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-0517 | HIGH | 8.8 | 21.7% | Jan 16, 2024 | Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-0507 | HIGH | 8.8 | 65.8% | Jan 16, 2024 | An attacker with access to a Management Console user account with the editor role could escalate privileges through a co... |
| CVE-2024-23347 | HIGH | 7.8 | 0.3% | Jan 16, 2024 | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file ... |
| CVE-2024-22628 | HIGH | 7.2 | 0.6% | Jan 16, 2024 | Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&dat... |
| CVE-2024-22627 | HIGH | 7.2 | 0.7% | Jan 16, 2024 | Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distrib... |
| CVE-2024-22626 | HIGH | 7.2 | 0.7% | Jan 16, 2024 | Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retaile... |
| CVE-2024-22625 | HIGH | 7.2 | 0.7% | Jan 16, 2024 | Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_categor... |
| CVE-2024-0582 | HIGH | 7.8 | 12.8% | Jan 16, 2024 | A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IOR... |
| CVE-2024-0567 | HIGH | 7.5 | 1.4% | Jan 16, 2024 | A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed tr... |
| CVE-2024-0553 | HIGH | 7.5 | 1.6% | Jan 16, 2024 | A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ fro... |
| CVE-2024-0555 | HIGH | 8 | 0.2% | Jan 16, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated use... |
| CVE-2024-21674 | HIGH | 7.5 | 1.8% | Jan 16, 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center ... |
| CVE-2024-21673 | HIGH | 8.8 | 1.5% | Jan 16, 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center... |
| CVE-2024-21672 | HIGH | 8.8 | 1.4% | Jan 16, 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now