2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6991HIGH8.8Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-6989HIGH8.8Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap c...
CVE-2024-6988HIGH8.8Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially expl...
CVE-2024-6720HIGH8.8The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to m...
CVE-2024-43113MEDIUM6.1The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects F...
CVE-2024-43112MEDIUM6.1Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects F...
CVE-2024-43111MEDIUM6.1Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vuln...
CVE-2024-41616CRITICAL9.8D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
CVE-2024-41333MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to ex...
CVE-2024-39751MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2024-39228CRITICAL9.8GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/...
CVE-2024-39226CRITICAL9.8GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/...
CVE-2024-39225CRITICAL9.8GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/...
CVE-2024-23483CRITICAL9.8An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue ...
CVE-2024-23464MEDIUM4.9In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Z...
CVE-2024-23460HIGH7.8The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrar...
CVE-2024-23458HIGH7.8While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks,...
CVE-2024-23456HIGH7.5Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connec...
CVE-2024-7552HIGH8.8A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is t...
CVE-2024-36424MEDIUM5.5K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of ...
CVE-2024-41913HIGH8.8A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware fla...
CVE-2024-41911MEDIUM5.4A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not...
CVE-2024-41910MEDIUM6.1A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware con...
CVE-2024-41226HIGH7.8A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary ...
CVE-2024-40101MEDIUM6.1A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unaut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now