2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9123HIGH8.8Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds m...
CVE-2024-9122HIGH8.8Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory a...
CVE-2024-9121HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perf...
CVE-2024-9120HIGH8.8Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially explo...
CVE-2024-9063Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2143 Reason: This candidate is a re...
CVE-2024-8942HIGH8.2Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input vali...
CVE-2024-8941MEDIUM5.3Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “su...
CVE-2024-8940CRITICAL9.8Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptca...
CVE-2024-8919MEDIUM5.4The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti...
CVE-2024-8917MEDIUM5.4The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-8914HIGH7.2The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulner...
CVE-2024-8878CRITICAL9.8The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin pa...
CVE-2024-8877CRITICAL9.8Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only li...
CVE-2024-8801MEDIUM4.3The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t...
CVE-2024-8497HIGH8.7Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could...
CVE-2024-8437MEDIUM4.3The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin...
CVE-2024-8436CRITICAL9.9The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId...
CVE-2024-8291MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A ...
CVE-2024-8267MEDIUM5.4The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable ...
CVE-2024-8103MEDIUM5.4The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in ...
CVE-2024-8067MEDIUM5.8In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument inject...
CVE-2024-7398MEDIUM5.4Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addit...
CVE-2024-47048MEDIUM5.4Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release no...
CVE-2024-46957CRITICAL9.8Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because...
CVE-2024-46936HIGH7.5Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now