2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25697 | MEDIUM | 5.4 | 0.4% | Apr 4, 2024 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, a... |
| CVE-2024-25696 | MEDIUM | 4.8 | 0.4% | Apr 4, 2024 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, a... |
| CVE-2024-25695 | HIGH | 7.2 | 0.5% | Apr 4, 2024 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, a... |
| CVE-2024-25693 | CRITICAL | 9.9 | 1.3% | Apr 4, 2024 | There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authe... |
| CVE-2024-25692 | MEDIUM | 5.4 | 0.2% | Apr 4, 2024 | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some c... |
| CVE-2024-25690 | MEDIUM | 4.7 | 0.5% | Apr 4, 2024 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unau... |
| CVE-2024-30263 | HIGH | 7.7 | 0.5% | Apr 4, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF a... |
| CVE-2024-31215 | MEDIUM | 4.3 | 0.5% | Apr 4, 2024 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo... |
| CVE-2024-31209 | MEDIUM | 5.3 | 0.2% | Apr 4, 2024 | oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling... |
| CVE-2024-31207 | MEDIUM | 5.9 | 0.7% | Apr 4, 2024 | Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend develo... |
| CVE-2024-30266 | MEDIUM | 5.5 | 0.3% | Apr 4, 2024 | wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its develo... |
| CVE-2024-30260 | MEDIUM | 4.3 | 0.7% | Apr 4, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea... |
| CVE-2024-2103 | MEDIUM | 6.5 | 0.5% | Apr 4, 2024 | Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the follow... |
| CVE-2024-3299 | HIGH | 7.8 | 0.4% | Apr 4, 2024 | Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedur... |
| CVE-2024-3298 | HIGH | 7.8 | 0.3% | Apr 4, 2024 | Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOL... |
| CVE-2024-3250 | MEDIUM | 6.5 | 0.2% | Apr 4, 2024 | It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v... |
| CVE-2024-3116 | CRITICAL | 9.8 | 64.8% | Apr 4, 2024 | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vu... |
| CVE-2024-30261 | LOW | 3.5 | 0.8% | Apr 4, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `... |
| CVE-2024-30250 | HIGH | 7.5 | 0.3% | Apr 4, 2024 | Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy he... |
| CVE-2024-29191 | MEDIUM | 6.1 | 0.4% | Apr 4, 2024 | gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th... |
| CVE-2024-29182 | MEDIUM | 6.1 | 0.3% | Apr 4, 2024 | Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerabilit... |
| CVE-2024-28871 | HIGH | 7.5 | 0.8% | Apr 4, 2024 | LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malfor... |
| CVE-2024-28182 | MEDIUM | 5.3 | 85.0% | Apr 4, 2024 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.6... |
| CVE-2024-27919 | HIGH | 7.5 | 86.7% | Apr 4, 2024 | Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol sta... |
| CVE-2024-22189 | HIGH | 7.5 | 1.1% | Apr 4, 2024 | quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now