2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2633 | MEDIUM | 6.1 | 0.3% | Mar 19, 2024 | A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint ... |
| CVE-2024-2632 | HIGH | 7.5 | 0.5% | Mar 19, 2024 | A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot o... |
| CVE-2024-2616 | LOW | 2.7 | 0.7% | Mar 19, 2024 | To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to... |
| CVE-2024-2615 | CRITICAL | 9.8 | 0.6% | Mar 19, 2024 | Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-2614 | HIGH | 8.8 | 0.9% | Mar 19, 2024 | Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence ... |
| CVE-2024-2613 | HIGH | 7.5 | 0.5% | Mar 19, 2024 | Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption a... |
| CVE-2024-2612 | HIGH | 8.1 | 1.0% | Mar 19, 2024 | If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or po... |
| CVE-2024-2611 | MEDIUM | 5.5 | 0.6% | Mar 19, 2024 | A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissi... |
| CVE-2024-2610 | MEDIUM | 6.1 | 0.7% | Mar 19, 2024 | Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content ... |
| CVE-2024-2609 | MEDIUM | 6.1 | 0.6% | Mar 19, 2024 | The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjackin... |
| CVE-2024-2608 | HIGH | 8.4 | 0.4% | Mar 19, 2024 | `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experience... |
| CVE-2024-2607 | HIGH | 8.1 | 1.1% | Mar 19, 2024 | Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue onl... |
| CVE-2024-2606 | LOW | 3.7 | 0.4% | Mar 19, 2024 | Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointe... |
| CVE-2024-2605 | MEDIUM | 5.9 | 0.6% | Mar 19, 2024 | An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *N... |
| CVE-2024-1146 | MEDIUM | 6.1 | 0.3% | Mar 19, 2024 | Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability c... |
| CVE-2024-1145 | MEDIUM | 5.3 | 0.5% | Mar 19, 2024 | User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could... |
| CVE-2024-1144 | MEDIUM | 6.5 | 0.3% | Mar 19, 2024 | Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerabilit... |
| CVE-2024-27439 | MEDIUM | 6.5 | 0.7% | Mar 19, 2024 | An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. T... |
| CVE-2024-24683 | MEDIUM | 6.5 | 1.2% | Mar 19, 2024 | Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users ... |
| CVE-2024-25942 | MEDIUM | 6.8 | 0.2% | Mar 19, 2024 | Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high pri... |
| CVE-2024-22453 | MEDIUM | 6 | 0.2% | Mar 19, 2024 | Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could p... |
| CVE-2024-24043 | MEDIUM | 5.5 | 0.4% | Mar 19, 2024 | Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary co... |
| CVE-2024-24042 | HIGH | 8.8 | 1.4% | Mar 19, 2024 | Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary ... |
| CVE-2024-0055 | MEDIUM | 6.5 | 0.6% | Mar 19, 2024 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was... |
| CVE-2024-0054 | MEDIUM | 6.5 | 0.6% | Mar 19, 2024 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now