2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4775 | MEDIUM | 5.9 | 0.2% | May 14, 2024 | An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid ... |
| CVE-2024-4774 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for... |
| CVE-2024-4773 | HIGH | 7.5 | 0.5% | May 14, 2024 | When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This... |
| CVE-2024-4772 | MEDIUM | 5.9 | 0.2% | May 14, 2024 | An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vuln... |
| CVE-2024-4771 | HIGH | 8.6 | 0.5% | May 14, 2024 | A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have tri... |
| CVE-2024-4770 | HIGH | 8.8 | 0.6% | May 14, 2024 | When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability af... |
| CVE-2024-4769 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | When importing resources using Web Workers, error messages would distinguish the difference between `application/javascr... |
| CVE-2024-4768 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting per... |
| CVE-2024-4767 | MEDIUM | 4.3 | 0.5% | May 14, 2024 | If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the win... |
| CVE-2024-4766 | MEDIUM | 4.3 | 0.4% | May 14, 2024 | Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to pot... |
| CVE-2024-4765 | HIGH | 8.1 | 0.3% | May 14, 2024 | Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite anot... |
| CVE-2024-4764 | CRITICAL | 9.8 | 0.6% | May 14, 2024 | Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability a... |
| CVE-2024-4367 | HIGH | 8.8 | 72.6% | May 14, 2024 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c... |
| CVE-2024-33485 | CRITICAL | 9.8 | 0.7% | May 14, 2024 | SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote ... |
| CVE-2024-27110 | HIGH | 8.4 | 0.3% | May 14, 2024 | Elevation of privilege vulnerability in GE HealthCare EchoPAC products |
| CVE-2024-31491 | HIGH | 8.8 | 0.8% | May 14, 2024 | A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandb... |
| CVE-2024-31488 | CRITICAL | 9 | 1.0% | May 14, 2024 | An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through... |
| CVE-2024-30059 | MEDIUM | 5.5 | 0.6% | May 14, 2024 | Microsoft Intune for Android Mobile Application Management Tampering Vulnerability |
| CVE-2024-30054 | MEDIUM | 6.5 | 1.7% | May 14, 2024 | Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability |
| CVE-2024-30053 | MEDIUM | 5.4 | 1.0% | May 14, 2024 | Azure Migrate Cross-Site Scripting Vulnerability |
| CVE-2024-30051 | HIGH | 7.8 | 5.7% | May 14, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2024-30050 | MEDIUM | 5.4 | 11.5% | May 14, 2024 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-30049 | HIGH | 7.8 | 0.7% | May 14, 2024 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| CVE-2024-30048 | MEDIUM | 4.1 | 1.0% | May 14, 2024 | Dynamics 365 Customer Insights Spoofing Vulnerability |
| CVE-2024-30047 | MEDIUM | 4.1 | 1.0% | May 14, 2024 | Dynamics 365 Customer Insights Spoofing Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now