2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25697MEDIUM5.4There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, a...
CVE-2024-25696MEDIUM4.8There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, a...
CVE-2024-25695HIGH7.2There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, a...
CVE-2024-25693CRITICAL9.9There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authe...
CVE-2024-25692MEDIUM5.4There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some c...
CVE-2024-25690MEDIUM4.7There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unau...
CVE-2024-30263HIGH7.7macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF a...
CVE-2024-31215MEDIUM4.3Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo...
CVE-2024-31209MEDIUM5.3oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling...
CVE-2024-31207MEDIUM5.9Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend develo...
CVE-2024-30266MEDIUM5.5wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its develo...
CVE-2024-30260MEDIUM4.3Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea...
CVE-2024-2103MEDIUM6.5 Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the follow...
CVE-2024-3299HIGH7.8Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedur...
CVE-2024-3298HIGH7.8Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOL...
CVE-2024-3250MEDIUM6.5It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v...
CVE-2024-3116CRITICAL9.8pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vu...
CVE-2024-30261LOW3.5Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `...
CVE-2024-30250HIGH7.5Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy he...
CVE-2024-29191MEDIUM6.1gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th...
CVE-2024-29182MEDIUM6.1Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerabilit...
CVE-2024-28871HIGH7.5LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malfor...
CVE-2024-28182MEDIUM5.3nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.6...
CVE-2024-27919HIGH7.5Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol sta...
CVE-2024-22189HIGH7.5quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now