2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9928 | MEDIUM | 5.3 | 0.4% | Nov 26, 2024 | A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, thi... |
| CVE-2024-9461 | HIGH | 7.2 | 1.0% | Nov 26, 2024 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo... |
| CVE-2024-8236 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-53976 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, maki... |
| CVE-2024-53975 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to... |
| CVE-2024-11708 | MEDIUM | 6.5 | 0.3% | Nov 26, 2024 | Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This... |
| CVE-2024-11706 | MEDIUM | 6.5 | 0.5% | Nov 26, 2024 | A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Ut... |
| CVE-2024-11705 | CRITICAL | 9.1 | 0.7% | Nov 26, 2024 | `NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segme... |
| CVE-2024-11704 | CRITICAL | 9.8 | 0.9% | Nov 26, 2024 | A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specif... |
| CVE-2024-11703 | MEDIUM | 5.7 | 0.2% | Nov 26, 2024 | On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authenticatio... |
| CVE-2024-11702 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored da... |
| CVE-2024-11701 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could hav... |
| CVE-2024-11700 | HIGH | 8.1 | 0.5% | Nov 26, 2024 | Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to use... |
| CVE-2024-11699 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence ... |
| CVE-2024-11698 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mo... |
| CVE-2024-11697 | HIGH | 8.8 | 0.8% | Nov 26, 2024 | When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"... |
| CVE-2024-11696 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver... |
| CVE-2024-11695 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resultin... |
| CVE-2024-11694 | MEDIUM | 6.1 | 0.5% | Nov 26, 2024 | Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS thr... |
| CVE-2024-11693 | CRITICAL | 9.8 | 0.8% | Nov 26, 2024 | The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Wind... |
| CVE-2024-11692 | MEDIUM | 4.3 | 0.5% | Nov 26, 2024 | An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possib... |
| CVE-2024-11691 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corrupti... |
| CVE-2024-51569 | HIGH | 7.5 | 1.2% | Nov 26, 2024 | Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l... |
| CVE-2024-47250 | MEDIUM | 5 | 0.7% | Nov 26, 2024 | Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou... |
| CVE-2024-47249 | MEDIUM | 5 | 0.6% | Nov 26, 2024 | Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from control... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now