2024 CVE Vulnerabilities

39,220 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10467HIGH8.8Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ...
CVE-2024-10466HIGH7.5By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ...
CVE-2024-10459HIGH7.5An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras...
CVE-2024-10458HIGH7.5A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vu...
CVE-2024-49650HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xarbo BuddyPress G...
CVE-2024-49648HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi SVG Capt...
CVE-2024-49647HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carl Alberto Simpl...
CVE-2024-49646HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ioannup Code Gener...
CVE-2024-49678HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js a...
CVE-2024-10436HIGH8.8The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
CVE-2024-50481HIGH8.8Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E...
CVE-2024-47401HIGH7.5Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b...
CVE-2024-22065HIGH8.8There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis in...
CVE-2024-50088HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free in add_inode_...
CVE-2024-50086HIGH7In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off Th...
CVE-2024-50083HIGH7.5In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmi...
CVE-2024-50074HIGH7.8In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access ...
CVE-2024-50073HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Fix use-after-free in gsm_cleanup_mux ...
CVE-2024-50071HIGH7.8In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl...
CVE-2024-44256HIGH8.6The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1...
CVE-2024-48594HIGH8.8File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f...
CVE-2024-48177HIGH8.8MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
CVE-2024-44289HIGH7.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-44285HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.1 and iPadOS 18.1, m...
CVE-2024-44277HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now