2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25697 | MEDIUM | 5.4 | 0.4% | Apr 4, 2024 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, a... |
| CVE-2024-25696 | MEDIUM | 4.8 | 0.4% | Apr 4, 2024 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, a... |
| CVE-2024-25692 | MEDIUM | 5.4 | 0.2% | Apr 4, 2024 | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some c... |
| CVE-2024-25690 | MEDIUM | 4.7 | 0.5% | Apr 4, 2024 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unau... |
| CVE-2024-31215 | MEDIUM | 4.3 | 0.5% | Apr 4, 2024 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo... |
| CVE-2024-31209 | MEDIUM | 5.3 | 0.2% | Apr 4, 2024 | oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling... |
| CVE-2024-31207 | MEDIUM | 5.9 | 0.7% | Apr 4, 2024 | Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend develo... |
| CVE-2024-30266 | MEDIUM | 5.5 | 0.3% | Apr 4, 2024 | wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its develo... |
| CVE-2024-30260 | MEDIUM | 4.3 | 0.7% | Apr 4, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea... |
| CVE-2024-2103 | MEDIUM | 6.5 | 0.5% | Apr 4, 2024 | Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the follow... |
| CVE-2024-3250 | MEDIUM | 6.5 | 0.2% | Apr 4, 2024 | It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v... |
| CVE-2024-29191 | MEDIUM | 6.1 | 0.4% | Apr 4, 2024 | gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th... |
| CVE-2024-29182 | MEDIUM | 6.1 | 0.3% | Apr 4, 2024 | Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerabilit... |
| CVE-2024-28182 | MEDIUM | 5.3 | 85.0% | Apr 4, 2024 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.6... |
| CVE-2024-3296 | MEDIUM | 5.9 | 0.4% | Apr 4, 2024 | A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext ac... |
| CVE-2024-3262 | MEDIUM | 5.5 | 0.3% | Apr 4, 2024 | Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with lo... |
| CVE-2024-26809 | MEDIUM | 5.5 | 0.3% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: release elements in clon... |
| CVE-2024-26807 | MEDIUM | 5.5 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: Both cadence-quadspi ->runtime_suspend() and ->runt... |
| CVE-2024-26806 | MEDIUM | 5.5 | 0.1% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-qspi: remove system-wide suspend helpe... |
| CVE-2024-26805 | MEDIUM | 5.5 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: netlink: Fix kernel-infoleak-after-free in __skb_da... |
| CVE-2024-26803 | MEDIUM | 5.5 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: veth: clear GRO when clearing XDP even when do... |
| CVE-2024-26802 | MEDIUM | 5.5 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: stmmac: Clear variable when destroying workqueue C... |
| CVE-2024-26801 | MEDIUM | 5.5 | 0.3% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_er... |
| CVE-2024-26798 | MEDIUM | 5.5 | 0.3% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do... |
| CVE-2024-26796 | MEDIUM | 5.5 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: drivers: perf: ctr_get_width function for legacy is... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now