2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9961HIGH8.8Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced ...
CVE-2024-9960HIGH7.5Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-9959HIGH8.8Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the ren...
CVE-2024-9958MEDIUM4.3Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to pe...
CVE-2024-9957HIGH8.8Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to en...
CVE-2024-9956HIGH7.8Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local att...
CVE-2024-9955HIGH8.8Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exp...
CVE-2024-9954HIGH8.8Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-9594HIGH8.1A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable...
CVE-2024-9486CRITICAL9.8A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable...
CVE-2024-48783HIGH7.5An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postg...
CVE-2024-48782CRITICAL9.8File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via ...
CVE-2024-48781CRITICAL9.8An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary...
CVE-2024-48779CRITICAL9.8An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary co...
CVE-2024-48714MEDIUM6.5In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which...
CVE-2024-48713MEDIUM6.5In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, whi...
CVE-2024-48712MEDIUM6.5In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can...
CVE-2024-48710MEDIUM6.5In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, wh...
CVE-2024-48411CRITICAL9.8itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload...
CVE-2024-44775HIGH7.5kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the b...
CVE-2024-41311HIGH8.1In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with fo...
CVE-2024-31955MEDIUM4.9An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fau...
CVE-2024-49195CRITICAL9.8Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
CVE-2024-44337MEDIUM5.1The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to p...
CVE-2024-21286MEDIUM5.4Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: E...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now