2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0836 | MEDIUM | 4.3 | 0.4% | Jan 31, 2024 | The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2024-22236 | MEDIUM | 5.5 | 0.2% | Jan 31, 2024 | In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.... |
| CVE-2024-0914 | MEDIUM | 5.9 | 0.9% | Jan 31, 2024 | A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 pad... |
| CVE-2024-1069 | HIGH | 7.2 | 1.2% | Jan 31, 2024 | The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio... |
| CVE-2024-23745 | CRITICAL | 9.8 | 2.0% | Jan 31, 2024 | In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to exec... |
| CVE-2024-22569 | MEDIUM | 5.4 | 0.5% | Jan 31, 2024 | Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a craft... |
| CVE-2024-23834 | MEDIUM | 6.1 | 0.5% | Jan 30, 2024 | Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in s... |
| CVE-2024-1077 | HIGH | 8.8 | 0.9% | Jan 30, 2024 | Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-1060 | HIGH | 8.8 | 0.9% | Jan 30, 2024 | Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap ... |
| CVE-2024-1059 | HIGH | 8.8 | 0.9% | Jan 30, 2024 | Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially expl... |
| CVE-2024-24567 | MEDIUM | 5.3 | 0.5% | Jan 30, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in b... |
| CVE-2024-24558 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tans... |
| CVE-2024-24556 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable t... |
| CVE-2024-23841 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nex... |
| CVE-2024-21388 | MEDIUM | 6.5 | 32.0% | Jan 30, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2024-1036 | CRITICAL | 9.8 | 0.9% | Jan 30, 2024 | A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon o... |
| CVE-2024-24565 | MEDIUM | 6.5 | 3.1% | Jan 30, 2024 | CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. Th... |
| CVE-2024-23840 | MEDIUM | 5.5 | 0.3% | Jan 30, 2024 | GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a ta... |
| CVE-2024-23838 | HIGH | 7.5 | 0.5% | Jan 30, 2024 | TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain con... |
| CVE-2024-23825 | MEDIUM | 4.9 | 0.5% | Jan 30, 2024 | TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL... |
| CVE-2024-23647 | HIGH | 8.8 | 0.5% | Jan 30, 2024 | Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to c... |
| CVE-2024-22200 | MEDIUM | 5.3 | 0.3% | Jan 30, 2024 | vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate... |
| CVE-2024-22193 | MEDIUM | 4.3 | 0.3% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
| CVE-2024-21671 | LOW | 3.7 | 0.4% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
| CVE-2024-21653 | CRITICAL | 9.8 | 0.5% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now