2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10468 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. ... |
| CVE-2024-10467 | HIGH | 8.8 | 0.6% | Oct 29, 2024 | Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ... |
| CVE-2024-10466 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ... |
| CVE-2024-10465 | MEDIUM | 6.5 | 0.5% | Oct 29, 2024 | A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox... |
| CVE-2024-10464 | MEDIUM | 6.5 | 0.6% | Oct 29, 2024 | Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the brows... |
| CVE-2024-10463 | MEDIUM | 6.5 | 0.7% | Oct 29, 2024 | Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefo... |
| CVE-2024-10462 | MEDIUM | 6.5 | 0.5% | Oct 29, 2024 | Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox <... |
| CVE-2024-10461 | MEDIUM | 6.1 | 0.6% | Oct 29, 2024 | In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and d... |
| CVE-2024-10460 | MEDIUM | 5.3 | 0.3% | Oct 29, 2024 | The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vu... |
| CVE-2024-10459 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras... |
| CVE-2024-10458 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vu... |
| CVE-2024-49667 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asaduzzaman Abir L... |
| CVE-2024-49665 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Web Bricks ... |
| CVE-2024-49664 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chatplusjp chatplu... |
| CVE-2024-49663 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elenkadark uCAT – ... |
| CVE-2024-49662 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webgensis Simple L... |
| CVE-2024-49661 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lew Ayotte leenk.m... |
| CVE-2024-49660 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CampusExplorer Cam... |
| CVE-2024-49659 | MEDIUM | 5.4 | 0.2% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coub Coub coub all... |
| CVE-2024-49656 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fifthsegment Docum... |
| CVE-2024-49654 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marian Heddesheime... |
| CVE-2024-49651 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Royal WooComm... |
| CVE-2024-49650 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xarbo BuddyPress G... |
| CVE-2024-49648 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi SVG Capt... |
| CVE-2024-49647 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carl Alberto Simpl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now