2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0814 | MEDIUM | 6.5 | 0.3% | Jan 24, 2024 | Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof... |
| CVE-2024-0813 | HIGH | 8.8 | 0.4% | Jan 24, 2024 | Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to insta... |
| CVE-2024-0812 | HIGH | 8.8 | 0.5% | Jan 24, 2024 | Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to poten... |
| CVE-2024-0811 | MEDIUM | 4.3 | 0.6% | Jan 24, 2024 | Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced... |
| CVE-2024-0810 | MEDIUM | 4.3 | 0.4% | Jan 24, 2024 | Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a ... |
| CVE-2024-0809 | MEDIUM | 4.3 | 0.4% | Jan 24, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Aut... |
| CVE-2024-0808 | CRITICAL | 9.8 | 0.5% | Jan 24, 2024 | Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-0807 | HIGH | 8.8 | 0.5% | Jan 24, 2024 | Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-0806 | HIGH | 8.8 | 0.4% | Jan 24, 2024 | Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-0805 | MEDIUM | 4.3 | 0.4% | Jan 24, 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform d... |
| CVE-2024-0804 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to ... |
| CVE-2024-22497 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run a... |
| CVE-2024-23636 | CRITICAL | 9.8 | 0.8% | Jan 23, 2024 | SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while... |
| CVE-2024-23341 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, a... |
| CVE-2024-23330 | MEDIUM | 5.3 | 0.5% | Jan 23, 2024 | Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is... |
| CVE-2024-22417 | MEDIUM | 6.1 | 0.6% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` ... |
| CVE-2024-22205 | CRITICAL | 9.8 | 1.0% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize ... |
| CVE-2024-22204 | MEDIUM | 5.3 | 0.8% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when... |
| CVE-2024-22203 | CRITICAL | 9.8 | 1.0% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` d... |
| CVE-2024-22496 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login ... |
| CVE-2024-22490 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword ... |
| CVE-2024-23854 | — | — | — | Jan 23, 2024 | Rejected reason: This CVE ID was unused by the CNA. |
| CVE-2024-22663 | CRITICAL | 9.8 | 1.7% | Jan 23, 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg |
| CVE-2024-22662 | CRITICAL | 9.8 | 0.9% | Jan 23, 2024 | TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules |
| CVE-2024-22660 | CRITICAL | 9.8 | 0.9% | Jan 23, 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now