2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4259 | CRITICAL | 9.8 | 0.5% | Sep 3, 2024 | Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatServic... |
| CVE-2024-34463 | MEDIUM | 5.1 | 0.7% | Sep 3, 2024 | BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The p... |
| CVE-2024-8389 | CRITICAL | 9.8 | 0.5% | Sep 3, 2024 | Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-8388 | MEDIUM | 5.3 | 0.3% | Sep 3, 2024 | Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing th... |
| CVE-2024-8387 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence ... |
| CVE-2024-8386 | MEDIUM | 6.1 | 0.4% | Sep 3, 2024 | If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of anot... |
| CVE-2024-8385 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusi... |
| CVE-2024-8384 | CRITICAL | 9.8 | 0.7% | Sep 3, 2024 | The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right ... |
| CVE-2024-8383 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that... |
| CVE-2024-8382 | HIGH | 8.8 | 0.6% | Sep 3, 2024 | Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for th... |
| CVE-2024-8381 | CRITICAL | 9.8 | 4.4% | Sep 3, 2024 | A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t... |
| CVE-2024-8371 | — | — | — | Sep 3, 2024 | Rejected reason: Duplicate of CVE-2024-45305. |
| CVE-2024-6232 | HIGH | 7.5 | 2.2% | Sep 3, 2024 | There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking... |
| CVE-2024-44921 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac... |
| CVE-2024-44920 | MEDIUM | 6.1 | 0.3% | Sep 3, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to e... |
| CVE-2024-6473 | HIGH | 7.8 | 0.7% | Sep 3, 2024 | Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. |
| CVE-2024-45588 | HIGH | 8.1 | 0.4% | Sep 3, 2024 | This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A... |
| CVE-2024-41718 | — | — | — | Sep 3, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID. ConsultIDs: CVE-2024-39771. Reason: This CVE ID is a reservation d... |
| CVE-2024-8374 | HIGH | 7.8 | 0.4% | Sep 3, 2024 | UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/p... |
| CVE-2024-45587 | HIGH | 8.8 | 0.4% | Sep 3, 2024 | This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A... |
| CVE-2024-45586 | HIGH | 8.8 | 0.4% | Sep 3, 2024 | This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Tradi... |
| CVE-2024-3655 | HIGH | 7.8 | 0.2% | Sep 3, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2024-38811 | HIGH | 7.8 | 0.3% | Sep 3, 2024 | VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var... |
| CVE-2024-37136 | MEDIUM | 4.9 | 0.4% | Sep 3, 2024 | Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Ac... |
| CVE-2024-7261 | CRITICAL | 9.8 | 11.3% | Sep 3, 2024 | The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now