2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23904HIGH7.5Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' chara...
CVE-2024-23898HIGH8.8Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin valid...
CVE-2024-23648HIGH8.8Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to ...
CVE-2024-23641HIGH7.5SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/h...
CVE-2024-22141HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue af...
CVE-2024-22154HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects Sal...
CVE-2024-22301HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This i...
CVE-2024-22294HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This...
CVE-2024-22152HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is...
CVE-2024-22135HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.T...
CVE-2024-0813HIGH8.8Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to insta...
CVE-2024-0812HIGH8.8Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to poten...
CVE-2024-0807HIGH8.8Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea...
CVE-2024-0806HIGH8.8Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea...
CVE-2024-0804HIGH7.5Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to ...
CVE-2024-0755HIGH8.8Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence ...
CVE-2024-0751HIGH8.8A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Fi...
CVE-2024-0750HIGH8.8A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting...
CVE-2024-0745HIGH8.8The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially ex...
CVE-2024-0744HIGH7.5In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploit...
CVE-2024-0743HIGH7.5An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability af...
CVE-2024-22705HIGH7.8An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c c...
CVE-2024-23348HIGH8.8Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series ver...
CVE-2024-23182HIGH8.1Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versi...
CVE-2024-23180HIGH8.8Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series ver...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now