2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0814MEDIUM6.5Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof...
CVE-2024-0813HIGH8.8Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to insta...
CVE-2024-0812HIGH8.8Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to poten...
CVE-2024-0811MEDIUM4.3Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced...
CVE-2024-0810MEDIUM4.3Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a ...
CVE-2024-0809MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Aut...
CVE-2024-0808CRITICAL9.8Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap...
CVE-2024-0807HIGH8.8Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea...
CVE-2024-0806HIGH8.8Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea...
CVE-2024-0805MEDIUM4.3Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform d...
CVE-2024-0804HIGH7.5Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to ...
CVE-2024-22497MEDIUM6.1Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run a...
CVE-2024-23636CRITICAL9.8SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while...
CVE-2024-23341MEDIUM6.1TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, a...
CVE-2024-23330MEDIUM5.3Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is...
CVE-2024-22417MEDIUM6.1Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` ...
CVE-2024-22205CRITICAL9.8Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize ...
CVE-2024-22204MEDIUM5.3Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when...
CVE-2024-22203CRITICAL9.8Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` d...
CVE-2024-22496MEDIUM6.1Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login ...
CVE-2024-22490MEDIUM6.1Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword ...
CVE-2024-23854Rejected reason: This CVE ID was unused by the CNA.
CVE-2024-22663CRITICAL9.8TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
CVE-2024-22662CRITICAL9.8TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules
CVE-2024-22660CRITICAL9.8TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now