2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5691 | MEDIUM | 4.7 | 0.7% | Jun 11, 2024 | By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if click... |
| CVE-2024-5690 | MEDIUM | 4.3 | 0.7% | Jun 11, 2024 | By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were fun... |
| CVE-2024-5689 | MEDIUM | 4.3 | 0.4% | Jun 11, 2024 | In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button ... |
| CVE-2024-5688 | HIGH | 8.1 | 1.1% | Jun 11, 2024 | If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. ... |
| CVE-2024-5687 | MEDIUM | 5.3 | 0.4% | Jun 11, 2024 | If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new ... |
| CVE-2024-2462 | MEDIUM | 6.8 | 0.2% | Jun 11, 2024 | Allow attackers to intercept or falsify data exchanges between the client and the server |
| CVE-2024-2461 | MEDIUM | 6.9 | 0.5% | Jun 11, 2024 | If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccess... |
| CVE-2024-36266 | HIGH | 7.8 | 0.2% | Jun 11, 2024 | A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects... |
| CVE-2024-35303 | HIGH | 7.8 | 0.3% | Jun 11, 2024 | A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant S... |
| CVE-2024-35292 | HIGH | 8.8 | 0.4% | Jun 11, 2024 | A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200... |
| CVE-2024-35212 | MEDIUM | 6.9 | 0.3% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected a... |
| CVE-2024-35211 | MEDIUM | 6.8 | 0.2% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w... |
| CVE-2024-35210 | MEDIUM | 5.1 | 0.1% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w... |
| CVE-2024-35209 | MEDIUM | 6.9 | 0.3% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w... |
| CVE-2024-35208 | MEDIUM | 5.5 | 0.1% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w... |
| CVE-2024-35207 | HIGH | 7.8 | 0.2% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interf... |
| CVE-2024-35206 | HIGH | 8.5 | 0.3% | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected a... |
| CVE-2024-33500 | HIGH | 7.4 | 0.3% | Jun 11, 2024 | A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Application... |
| CVE-2024-5829 | MEDIUM | 5.3 | 0.3% | Jun 11, 2024 | A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is a... |
| CVE-2024-35685 | MEDIUM | 5.3 | 0.3% | Jun 11, 2024 | Missing Authorization vulnerability in Anders Norén Radcliffe 2.This issue affects Radcliffe 2: from n/a through 2.0.17. |
| CVE-2024-34813 | MEDIUM | 5.3 | 0.3% | Jun 11, 2024 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This iss... |
| CVE-2024-5825 | — | — | — | Jun 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5584 | MEDIUM | 6.4 | 0.3% | Jun 11, 2024 | The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-5398 | — | — | — | Jun 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-4387 | — | — | — | Jun 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now