2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25697MEDIUM5.4There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, a...
CVE-2024-25696MEDIUM4.8There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, a...
CVE-2024-25692MEDIUM5.4There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some c...
CVE-2024-25690MEDIUM4.7There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unau...
CVE-2024-31215MEDIUM4.3Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo...
CVE-2024-31209MEDIUM5.3oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling...
CVE-2024-31207MEDIUM5.9Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend develo...
CVE-2024-30266MEDIUM5.5wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its develo...
CVE-2024-30260MEDIUM4.3Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea...
CVE-2024-2103MEDIUM6.5 Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the follow...
CVE-2024-3250MEDIUM6.5It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v...
CVE-2024-29191MEDIUM6.1gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th...
CVE-2024-29182MEDIUM6.1Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerabilit...
CVE-2024-28182MEDIUM5.3nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.6...
CVE-2024-3296MEDIUM5.9A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext ac...
CVE-2024-3262MEDIUM5.5Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with lo...
CVE-2024-26809MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: release elements in clon...
CVE-2024-26807MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Both cadence-quadspi ->runtime_suspend() and ->runt...
CVE-2024-26806MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-qspi: remove system-wide suspend helpe...
CVE-2024-26805MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netlink: Fix kernel-infoleak-after-free in __skb_da...
CVE-2024-26803MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: veth: clear GRO when clearing XDP even when do...
CVE-2024-26802MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: stmmac: Clear variable when destroying workqueue C...
CVE-2024-26801MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_er...
CVE-2024-26798MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do...
CVE-2024-26796MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drivers: perf: ctr_get_width function for legacy is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now