2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9961 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced ... |
| CVE-2024-9960 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-9959 | HIGH | 8.8 | 0.3% | Oct 15, 2024 | Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the ren... |
| CVE-2024-9958 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to pe... |
| CVE-2024-9957 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to en... |
| CVE-2024-9956 | HIGH | 7.8 | 0.4% | Oct 15, 2024 | Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local att... |
| CVE-2024-9955 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exp... |
| CVE-2024-9954 | HIGH | 8.8 | 6.3% | Oct 15, 2024 | Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-9594 | HIGH | 8.1 | 1.6% | Oct 15, 2024 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable... |
| CVE-2024-9486 | CRITICAL | 9.8 | 2.2% | Oct 15, 2024 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable... |
| CVE-2024-48783 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postg... |
| CVE-2024-48782 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-48781 | CRITICAL | 9.8 | 0.7% | Oct 15, 2024 | An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary... |
| CVE-2024-48779 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary co... |
| CVE-2024-48714 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which... |
| CVE-2024-48713 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, whi... |
| CVE-2024-48712 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can... |
| CVE-2024-48710 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, wh... |
| CVE-2024-48411 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload... |
| CVE-2024-44775 | HIGH | 7.5 | 0.5% | Oct 15, 2024 | kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the b... |
| CVE-2024-41311 | HIGH | 8.1 | 0.8% | Oct 15, 2024 | In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with fo... |
| CVE-2024-31955 | MEDIUM | 4.9 | 0.2% | Oct 15, 2024 | An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fau... |
| CVE-2024-49195 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair |
| CVE-2024-44337 | MEDIUM | 5.1 | 0.5% | Oct 15, 2024 | The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to p... |
| CVE-2024-21286 | MEDIUM | 5.4 | 0.3% | Oct 15, 2024 | Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: E... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now