2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4259CRITICAL9.8Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatServic...
CVE-2024-34463MEDIUM5.1BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The p...
CVE-2024-8389CRITICAL9.8Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-8388MEDIUM5.3Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing th...
CVE-2024-8387CRITICAL9.8Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence ...
CVE-2024-8386MEDIUM6.1If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of anot...
CVE-2024-8385CRITICAL9.8A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusi...
CVE-2024-8384CRITICAL9.8The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right ...
CVE-2024-8383HIGH7.5Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that...
CVE-2024-8382HIGH8.8Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for th...
CVE-2024-8381CRITICAL9.8A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t...
CVE-2024-8371Rejected reason: Duplicate of CVE-2024-45305.
CVE-2024-6232HIGH7.5There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking...
CVE-2024-44921CRITICAL9.8SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac...
CVE-2024-44920MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to e...
CVE-2024-6473HIGH7.8Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-45588HIGH8.1This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A...
CVE-2024-41718Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID. ConsultIDs: CVE-2024-39771. Reason: This CVE ID is a reservation d...
CVE-2024-8374HIGH7.8UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/p...
CVE-2024-45587HIGH8.8This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A...
CVE-2024-45586HIGH8.8This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Tradi...
CVE-2024-3655HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2024-38811HIGH7.8VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var...
CVE-2024-37136MEDIUM4.9Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Ac...
CVE-2024-7261CRITICAL9.8The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now