2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-44807MEDIUM5.3A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition befor...
CVE-2024-44157MEDIUM5.5A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for W...
CVE-2024-9859HIGH8.8Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary co...
CVE-2024-47877HIGH7.5Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow ...
CVE-2024-46215MEDIUM6.5A vulnerability was discovered in KM08-708H-v1.1, There is a buffer overflow in the sub_445BDC() function within the /us...
CVE-2024-44734HIGH7.5Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a...
CVE-2024-44731MEDIUM4.7Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allow...
CVE-2024-44415MEDIUM6.5A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy f...
CVE-2024-44414HIGH8.8A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_...
CVE-2024-44413HIGH8.8A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgr...
CVE-2024-42018HIGH7.7An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration param...
CVE-2024-9046HIGH7.8A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elev...
CVE-2024-8376HIGH7.5In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after...
CVE-2024-6985MEDIUM4.4A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnera...
CVE-2024-5474MEDIUM5.5A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning softwar...
CVE-2024-4132HIGH7.8A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with ele...
CVE-2024-4131HIGH7.8A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevat...
CVE-2024-4130HIGH7.8A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with eleva...
CVE-2024-4089HIGH7.8A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elev...
CVE-2024-48827HIGH8.8An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the...
CVE-2024-48813HIGH8.8SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote...
CVE-2024-47509HIGH7.1An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juni...
CVE-2024-47508HIGH7.1An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juni...
CVE-2024-47507MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne...
CVE-2024-47506HIGH8.2A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unau...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now