2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2633MEDIUM6.1A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint ...
CVE-2024-2632HIGH7.5A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot o...
CVE-2024-2616LOW2.7To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to...
CVE-2024-2615CRITICAL9.8Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-2614HIGH8.8Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence ...
CVE-2024-2613HIGH7.5Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption a...
CVE-2024-2612HIGH8.1If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or po...
CVE-2024-2611MEDIUM5.5A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissi...
CVE-2024-2610MEDIUM6.1Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content ...
CVE-2024-2609MEDIUM6.1The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjackin...
CVE-2024-2608HIGH8.4`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experience...
CVE-2024-2607HIGH8.1Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue onl...
CVE-2024-2606LOW3.7Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointe...
CVE-2024-2605MEDIUM5.9An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *N...
CVE-2024-1146MEDIUM6.1Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability c...
CVE-2024-1145MEDIUM5.3User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could...
CVE-2024-1144MEDIUM6.5Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerabilit...
CVE-2024-27439MEDIUM6.5An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. T...
CVE-2024-24683MEDIUM6.5Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users ...
CVE-2024-25942MEDIUM6.8Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high pri...
CVE-2024-22453MEDIUM6Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could p...
CVE-2024-24043MEDIUM5.5Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary co...
CVE-2024-24042HIGH8.8Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary ...
CVE-2024-0055MEDIUM6.5Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was...
CVE-2024-0054MEDIUM6.5Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now