2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23904 | HIGH | 7.5 | 0.9% | Jan 24, 2024 | Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' chara... |
| CVE-2024-23898 | HIGH | 8.8 | 66.9% | Jan 24, 2024 | Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin valid... |
| CVE-2024-23648 | HIGH | 8.8 | 0.8% | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to ... |
| CVE-2024-23641 | HIGH | 7.5 | 0.8% | Jan 24, 2024 | SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/h... |
| CVE-2024-22141 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue af... |
| CVE-2024-22154 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects Sal... |
| CVE-2024-22301 | HIGH | 7.5 | 0.4% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This i... |
| CVE-2024-22294 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This... |
| CVE-2024-22152 | HIGH | 7.2 | 0.5% | Jan 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is... |
| CVE-2024-22135 | HIGH | 7.2 | 0.5% | Jan 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.T... |
| CVE-2024-0813 | HIGH | 8.8 | 0.4% | Jan 24, 2024 | Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to insta... |
| CVE-2024-0812 | HIGH | 8.8 | 0.5% | Jan 24, 2024 | Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to poten... |
| CVE-2024-0807 | HIGH | 8.8 | 0.5% | Jan 24, 2024 | Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-0806 | HIGH | 8.8 | 0.4% | Jan 24, 2024 | Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-0804 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to ... |
| CVE-2024-0755 | HIGH | 8.8 | 0.7% | Jan 23, 2024 | Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence ... |
| CVE-2024-0751 | HIGH | 8.8 | 0.6% | Jan 23, 2024 | A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Fi... |
| CVE-2024-0750 | HIGH | 8.8 | 0.8% | Jan 23, 2024 | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting... |
| CVE-2024-0745 | HIGH | 8.8 | 0.7% | Jan 23, 2024 | The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially ex... |
| CVE-2024-0744 | HIGH | 7.5 | 0.6% | Jan 23, 2024 | In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploit... |
| CVE-2024-0743 | HIGH | 7.5 | 1.3% | Jan 23, 2024 | An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability af... |
| CVE-2024-22705 | HIGH | 7.8 | 0.3% | Jan 23, 2024 | An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c c... |
| CVE-2024-23348 | HIGH | 8.8 | 0.7% | Jan 23, 2024 | Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series ver... |
| CVE-2024-23182 | HIGH | 8.1 | 0.7% | Jan 23, 2024 | Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versi... |
| CVE-2024-23180 | HIGH | 8.8 | 0.9% | Jan 23, 2024 | Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series ver... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now