2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0755 | HIGH | 8.8 | 0.7% | Jan 23, 2024 | Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence ... |
| CVE-2024-0754 | MEDIUM | 6.5 | 0.4% | Jan 23, 2024 | Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122. |
| CVE-2024-0753 | MEDIUM | 6.5 | 0.7% | Jan 23, 2024 | In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox ... |
| CVE-2024-0752 | MEDIUM | 6.5 | 0.4% | Jan 23, 2024 | A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This c... |
| CVE-2024-0751 | HIGH | 8.8 | 0.6% | Jan 23, 2024 | A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Fi... |
| CVE-2024-0750 | HIGH | 8.8 | 0.8% | Jan 23, 2024 | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting... |
| CVE-2024-0749 | MEDIUM | 4.3 | 0.3% | Jan 23, 2024 | A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the addres... |
| CVE-2024-0748 | MEDIUM | 4.3 | 0.4% | Jan 23, 2024 | A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitra... |
| CVE-2024-0747 | MEDIUM | 6.5 | 0.6% | Jan 23, 2024 | When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overr... |
| CVE-2024-0746 | MEDIUM | 6.5 | 0.7% | Jan 23, 2024 | A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox... |
| CVE-2024-0745 | HIGH | 8.8 | 0.7% | Jan 23, 2024 | The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially ex... |
| CVE-2024-0744 | HIGH | 7.5 | 0.6% | Jan 23, 2024 | In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploit... |
| CVE-2024-0743 | HIGH | 7.5 | 1.3% | Jan 23, 2024 | An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability af... |
| CVE-2024-0742 | MEDIUM | 4.3 | 0.6% | Jan 23, 2024 | It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to ... |
| CVE-2024-0741 | MEDIUM | 6.5 | 2.2% | Jan 23, 2024 | An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable cr... |
| CVE-2024-22705 | HIGH | 7.8 | 0.3% | Jan 23, 2024 | An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c c... |
| CVE-2024-22076 | CRITICAL | 9.8 | 1.1% | Jan 23, 2024 | MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP script... |
| CVE-2024-0703 | MEDIUM | 4.8 | 0.3% | Jan 23, 2024 | The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via stic... |
| CVE-2024-23348 | HIGH | 8.8 | 0.7% | Jan 23, 2024 | Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series ver... |
| CVE-2024-23183 | MEDIUM | 5.4 | 0.4% | Jan 23, 2024 | Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions... |
| CVE-2024-23182 | HIGH | 8.1 | 0.7% | Jan 23, 2024 | Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versi... |
| CVE-2024-23181 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions... |
| CVE-2024-23180 | HIGH | 8.8 | 0.9% | Jan 23, 2024 | Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series ver... |
| CVE-2024-23851 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, ... |
| CVE-2024-23850 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and cra... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now