2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33897 | CRITICAL | 9.1 | 0.7% | Aug 6, 2024 | A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another d... |
| CVE-2024-30170 | CRITICAL | 9.1 | 0.6% | Aug 6, 2024 | PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1,... |
| CVE-2024-7551 | MEDIUM | 4.9 | 0.9% | Aug 6, 2024 | A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func... |
| CVE-2024-7531 | MEDIUM | 6.5 | 0.4% | Aug 6, 2024 | Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on a... |
| CVE-2024-7530 | HIGH | 8.8 | 0.4% | Aug 6, 2024 | Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129. |
| CVE-2024-7529 | MEDIUM | 6.5 | 0.5% | Aug 6, 2024 | The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into gr... |
| CVE-2024-7528 | HIGH | 8.8 | 0.5% | Aug 6, 2024 | Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Fir... |
| CVE-2024-7527 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox ... |
| CVE-2024-7526 | MEDIUM | 6.5 | 0.5% | Aug 6, 2024 | ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak s... |
| CVE-2024-7525 | HIGH | 8.1 | 0.6% | Aug 6, 2024 | It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and ... |
| CVE-2024-7524 | MEDIUM | 6.1 | 0.5% | Aug 6, 2024 | Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a si... |
| CVE-2024-7523 | HIGH | 8.1 | 0.3% | Aug 6, 2024 | A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into gr... |
| CVE-2024-7522 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects... |
| CVE-2024-7521 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, F... |
| CVE-2024-7520 | HIGH | 8.8 | 0.6% | Aug 6, 2024 | A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulner... |
| CVE-2024-7519 | CRITICAL | 9.6 | 0.6% | Aug 6, 2024 | Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged ... |
| CVE-2024-7518 | MEDIUM | 6.5 | 0.5% | Aug 6, 2024 | Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spo... |
| CVE-2024-6359 | CRITICAL | 9.8 | 0.3% | Aug 6, 2024 | Privilege escalation vulnerability identified in OpenText ArcSight Intelligence. |
| CVE-2024-6358 | HIGH | 8.8 | 0.3% | Aug 6, 2024 | Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence. |
| CVE-2024-6357 | HIGH | 8.8 | 0.3% | Aug 6, 2024 | Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence. |
| CVE-2024-43114 | HIGH | 7.8 | 0.2% | Aug 6, 2024 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions |
| CVE-2024-33994 | MEDIUM | 6.1 | 0.2% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could crea... |
| CVE-2024-33993 | MEDIUM | 6.1 | 0.2% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could crea... |
| CVE-2024-33992 | MEDIUM | 6.1 | 0.2% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could expl... |
| CVE-2024-33991 | MEDIUM | 6.1 | 0.2% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could expl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now