2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44050 | MEDIUM | 5.4 | 0.3% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cryout-creations V... |
| CVE-2024-44049 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber... |
| CVE-2024-44047 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress... |
| CVE-2024-44009 | MEDIUM | 6.1 | 0.3% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WC Lovers WCFM Mar... |
| CVE-2024-44008 | MEDIUM | 5.4 | 0.3% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Ma... |
| CVE-2024-44007 | MEDIUM | 6.1 | 0.3% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT T... |
| CVE-2024-43985 | MEDIUM | 4.8 | 0.3% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople ... |
| CVE-2024-43977 | MEDIUM | 5.4 | 0.3% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus ... |
| CVE-2024-43938 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name... |
| CVE-2024-37985 | MEDIUM | 5.6 | 0.7% | Sep 17, 2024 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2024-8909 | MEDIUM | 4.3 | 0.3% | Sep 17, 2024 | Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform U... |
| CVE-2024-8908 | MEDIUM | 4.3 | 0.3% | Sep 17, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI... |
| CVE-2024-8907 | MEDIUM | 6.1 | 0.3% | Sep 17, 2024 | Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who... |
| CVE-2024-8906 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a use... |
| CVE-2024-46976 | MEDIUM | 5.4 | 0.3% | Sep 17, 2024 | Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs ... |
| CVE-2024-45816 | MEDIUM | 6.5 | 0.7% | Sep 17, 2024 | Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDoc... |
| CVE-2024-45815 | MEDIUM | 6.5 | 0.5% | Sep 17, 2024 | Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstag... |
| CVE-2024-8951 | MEDIUM | 6.1 | 0.4% | Sep 17, 2024 | A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu... |
| CVE-2024-45812 | MEDIUM | 6.4 | 0.6% | Sep 17, 2024 | Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobb... |
| CVE-2024-45811 | MEDIUM | 4.8 | 1.0% | Sep 17, 2024 | Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be retu... |
| CVE-2024-45606 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rul... |
| CVE-2024-45605 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user is... |
| CVE-2024-45604 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the docume... |
| CVE-2024-8660 | MEDIUM | 4.8 | 0.3% | Sep 17, 2024 | Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. S... |
| CVE-2024-45803 | MEDIUM | 6.1 | 0.4% | Sep 17, 2024 | Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now