2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9341HIGH8.2A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa...
CVE-2024-46083MEDIUM5.4Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p...
CVE-2024-46081MEDIUM5.4Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p...
CVE-2024-46079MEDIUM6.1Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
CVE-2024-42514HIGH8.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen...
CVE-2024-31835MEDIUM4.8Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi...
CVE-2024-47608CRITICAL9.8Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromi...
CVE-2024-9403HIGH7.3Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-9402CRITICAL9.8Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence ...
CVE-2024-9401CRITICAL9.8Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b...
CVE-2024-9400HIGH8.8A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe...
CVE-2024-9399HIGH7.5A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d...
CVE-2024-9398MEDIUM5.3By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if...
CVE-2024-9397MEDIUM6.1A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permiss...
CVE-2024-9396HIGH8.8It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj...
CVE-2024-9395MEDIUM5.3A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in th...
CVE-2024-9394HIGH7.5An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo...
CVE-2024-9393HIGH7.5An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js...
CVE-2024-9392CRITICAL9.8A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability aff...
CVE-2024-9391MEDIUM6.5A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr...
CVE-2024-47604MEDIUM6.1NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handli...
CVE-2024-47534HIGH8.2go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. Fo...
CVE-2024-47071MEDIUM6.8OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authent...
CVE-2024-25660CRITICAL9The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacke...
CVE-2024-25659HIGH7.2In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now