2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33897CRITICAL9.1A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another d...
CVE-2024-30170CRITICAL9.1PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1,...
CVE-2024-7551MEDIUM4.9A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func...
CVE-2024-7531MEDIUM6.5Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on a...
CVE-2024-7530HIGH8.8Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
CVE-2024-7529MEDIUM6.5The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into gr...
CVE-2024-7528HIGH8.8Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Fir...
CVE-2024-7527HIGH8.8Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox ...
CVE-2024-7526MEDIUM6.5ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak s...
CVE-2024-7525HIGH8.1It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and ...
CVE-2024-7524MEDIUM6.1Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a si...
CVE-2024-7523HIGH8.1A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into gr...
CVE-2024-7522HIGH8.8Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects...
CVE-2024-7521HIGH8.8Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, F...
CVE-2024-7520HIGH8.8A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulner...
CVE-2024-7519CRITICAL9.6Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged ...
CVE-2024-7518MEDIUM6.5Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spo...
CVE-2024-6359CRITICAL9.8Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
CVE-2024-6358HIGH8.8Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
CVE-2024-6357HIGH8.8Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
CVE-2024-43114HIGH7.8In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
CVE-2024-33994MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could crea...
CVE-2024-33993MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could crea...
CVE-2024-33992MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could expl...
CVE-2024-33991MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could expl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now