2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26010HIGH7.5A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, Fo...
CVE-2024-24703HIGH8.6Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4...
CVE-2024-23111MEDIUM4.8An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiO...
CVE-2024-23110HIGH7.8A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13...
CVE-2024-21754MEDIUM4.4A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 an...
CVE-2024-5189MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-35683MEDIUM5.3Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through ...
CVE-2024-35671MEDIUM4.3Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1...
CVE-2024-34442MEDIUM5.3Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4.
CVE-2024-2013CRITICAL10An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited all...
CVE-2024-2012CRITICAL9.8vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow uninten...
CVE-2024-2011CRITICAL9.8A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denia...
CVE-2024-28023MEDIUM5.7A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or fun...
CVE-2024-28021HIGH7.4A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validatio...
CVE-2024-5702HIGH7.5Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects ...
CVE-2024-5701CRITICAL9.8Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-5700HIGH7Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidenc...
CVE-2024-5699CRITICAL9.8In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by ...
CVE-2024-5698MEDIUM6.1By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the ad...
CVE-2024-5697MEDIUM4.3A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Fire...
CVE-2024-5696HIGH8.6By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentiall...
CVE-2024-5695CRITICAL9.8If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an asserti...
CVE-2024-5694HIGH7.5An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section ...
CVE-2024-5693MEDIUM6.1Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another sit...
CVE-2024-5692MEDIUM6.5On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file w...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now