2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10467 | HIGH | 8.8 | 0.6% | Oct 29, 2024 | Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ... |
| CVE-2024-10466 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ... |
| CVE-2024-10459 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras... |
| CVE-2024-10458 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vu... |
| CVE-2024-49650 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xarbo BuddyPress G... |
| CVE-2024-49648 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi SVG Capt... |
| CVE-2024-49647 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carl Alberto Simpl... |
| CVE-2024-49646 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ioannup Code Gener... |
| CVE-2024-49678 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js a... |
| CVE-2024-10436 | HIGH | 8.8 | 0.7% | Oct 29, 2024 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,... |
| CVE-2024-50481 | HIGH | 8.8 | 0.4% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E... |
| CVE-2024-47401 | HIGH | 7.5 | 0.4% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b... |
| CVE-2024-22065 | HIGH | 8.8 | 1.2% | Oct 29, 2024 | There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis in... |
| CVE-2024-50088 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free in add_inode_... |
| CVE-2024-50086 | HIGH | 7 | 0.2% | Oct 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off Th... |
| CVE-2024-50083 | HIGH | 7.5 | 0.9% | Oct 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmi... |
| CVE-2024-50074 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access ... |
| CVE-2024-50073 | HIGH | 7.8 | 0.3% | Oct 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Fix use-after-free in gsm_cleanup_mux ... |
| CVE-2024-50071 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl... |
| CVE-2024-44256 | HIGH | 8.6 | 0.2% | Oct 28, 2024 | The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1... |
| CVE-2024-48594 | HIGH | 8.8 | 3.3% | Oct 28, 2024 | File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f... |
| CVE-2024-48177 | HIGH | 8.8 | 0.4% | Oct 28, 2024 | MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do. |
| CVE-2024-44289 | HIGH | 7.5 | 0.6% | Oct 28, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-44285 | HIGH | 7.8 | 0.7% | Oct 28, 2024 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.1 and iPadOS 18.1, m... |
| CVE-2024-44277 | HIGH | 7.8 | 0.2% | Oct 28, 2024 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now