2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9341 | HIGH | 8.2 | 1.0% | Oct 1, 2024 | A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa... |
| CVE-2024-46083 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p... |
| CVE-2024-46081 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p... |
| CVE-2024-46079 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter. |
| CVE-2024-42514 | HIGH | 8.1 | 0.4% | Oct 1, 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen... |
| CVE-2024-31835 | MEDIUM | 4.8 | 0.9% | Oct 1, 2024 | Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-47608 | CRITICAL | 9.8 | 0.6% | Oct 1, 2024 | Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromi... |
| CVE-2024-9403 | HIGH | 7.3 | 0.4% | Oct 1, 2024 | Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-9402 | CRITICAL | 9.8 | 0.6% | Oct 1, 2024 | Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence ... |
| CVE-2024-9401 | CRITICAL | 9.8 | 0.7% | Oct 1, 2024 | Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b... |
| CVE-2024-9400 | HIGH | 8.8 | 0.5% | Oct 1, 2024 | A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe... |
| CVE-2024-9399 | HIGH | 7.5 | 0.5% | Oct 1, 2024 | A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d... |
| CVE-2024-9398 | MEDIUM | 5.3 | 0.6% | Oct 1, 2024 | By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if... |
| CVE-2024-9397 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permiss... |
| CVE-2024-9396 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj... |
| CVE-2024-9395 | MEDIUM | 5.3 | 0.3% | Oct 1, 2024 | A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in th... |
| CVE-2024-9394 | HIGH | 7.5 | 0.5% | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo... |
| CVE-2024-9393 | HIGH | 7.5 | 0.4% | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js... |
| CVE-2024-9392 | CRITICAL | 9.8 | 0.5% | Oct 1, 2024 | A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability aff... |
| CVE-2024-9391 | MEDIUM | 6.5 | 0.3% | Oct 1, 2024 | A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr... |
| CVE-2024-47604 | MEDIUM | 6.1 | 0.7% | Oct 1, 2024 | NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handli... |
| CVE-2024-47534 | HIGH | 8.2 | 0.5% | Oct 1, 2024 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. Fo... |
| CVE-2024-47071 | MEDIUM | 6.8 | 0.5% | Oct 1, 2024 | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authent... |
| CVE-2024-25660 | CRITICAL | 9 | 0.5% | Oct 1, 2024 | The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacke... |
| CVE-2024-25659 | HIGH | 7.2 | 0.7% | Oct 1, 2024 | In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now