2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7973HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bo...
CVE-2024-7972HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perf...
CVE-2024-7971CRITICAL9.6Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a ...
CVE-2024-7969HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-7968HIGH8.8Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user ...
CVE-2024-7967HIGH8.8Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit h...
CVE-2024-7966HIGH8.8Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromise...
CVE-2024-7965HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl...
CVE-2024-7964HIGH8.8Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially ...
CVE-2024-6386HIGH8.8The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Tw...
CVE-2024-20486HIGH8.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2024-20466MEDIUM4.9A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2024-20417HIGH8.1Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote at...
CVE-2024-41572MEDIUM6.1Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function tha...
CVE-2024-20488MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2024-42786HIGH8.8A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to ...
CVE-2024-42785HIGH8.8A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an...
CVE-2024-42784CRITICAL9.8A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allow...
CVE-2024-42783CRITICAL9.8Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker ...
CVE-2024-42782CRITICAL9.8A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an...
CVE-2024-42781CRITICAL9.8A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote ...
CVE-2024-42780HIGH8.8An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management...
CVE-2024-42779HIGH8.8An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management...
CVE-2024-42778HIGH8.8An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Managem...
CVE-2024-42777CRITICAL9.8An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management Sys...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now