2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6991 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-6989 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-6988 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially expl... |
| CVE-2024-6720 | HIGH | 8.8 | 0.2% | Aug 6, 2024 | The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to m... |
| CVE-2024-43113 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects F... |
| CVE-2024-43112 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects F... |
| CVE-2024-43111 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vuln... |
| CVE-2024-41616 | CRITICAL | 9.8 | 0.8% | Aug 6, 2024 | D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service. |
| CVE-2024-41333 | MEDIUM | 6.1 | 0.5% | Aug 6, 2024 | A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to ex... |
| CVE-2024-39751 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2024-39228 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
| CVE-2024-39226 | CRITICAL | 9.8 | 20.6% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
| CVE-2024-39225 | CRITICAL | 9.8 | 14.5% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
| CVE-2024-23483 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue ... |
| CVE-2024-23464 | MEDIUM | 4.9 | 0.4% | Aug 6, 2024 | In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Z... |
| CVE-2024-23460 | HIGH | 7.8 | 0.1% | Aug 6, 2024 | The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrar... |
| CVE-2024-23458 | HIGH | 7.8 | 0.1% | Aug 6, 2024 | While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks,... |
| CVE-2024-23456 | HIGH | 7.5 | 0.2% | Aug 6, 2024 | Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connec... |
| CVE-2024-7552 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is t... |
| CVE-2024-36424 | MEDIUM | 5.5 | 1.0% | Aug 6, 2024 | K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of ... |
| CVE-2024-41913 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware fla... |
| CVE-2024-41911 | MEDIUM | 5.4 | 0.2% | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not... |
| CVE-2024-41910 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware con... |
| CVE-2024-41226 | HIGH | 7.8 | 0.5% | Aug 6, 2024 | A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary ... |
| CVE-2024-40101 | MEDIUM | 6.1 | 0.9% | Aug 6, 2024 | A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unaut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now