2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22380 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development ... |
| CVE-2024-21796 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creat... |
| CVE-2024-21765 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 a... |
| CVE-2024-23638 | MEDIUM | 6.5 | 60.1% | Jan 24, 2024 | Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable ... |
| CVE-2024-23633 | MEDIUM | 6.1 | 0.6% | Jan 24, 2024 | Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote w... |
| CVE-2024-23453 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retri... |
| CVE-2024-0814 | MEDIUM | 6.5 | 0.3% | Jan 24, 2024 | Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof... |
| CVE-2024-0811 | MEDIUM | 4.3 | 0.6% | Jan 24, 2024 | Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced... |
| CVE-2024-0810 | MEDIUM | 4.3 | 0.4% | Jan 24, 2024 | Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a ... |
| CVE-2024-0809 | MEDIUM | 4.3 | 0.4% | Jan 24, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Aut... |
| CVE-2024-0805 | MEDIUM | 4.3 | 0.4% | Jan 24, 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform d... |
| CVE-2024-22497 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run a... |
| CVE-2024-23341 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, a... |
| CVE-2024-23330 | MEDIUM | 5.3 | 0.5% | Jan 23, 2024 | Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is... |
| CVE-2024-22417 | MEDIUM | 6.1 | 0.6% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` ... |
| CVE-2024-22204 | MEDIUM | 5.3 | 0.8% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when... |
| CVE-2024-22496 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login ... |
| CVE-2024-22490 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword ... |
| CVE-2024-0754 | MEDIUM | 6.5 | 0.4% | Jan 23, 2024 | Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122. |
| CVE-2024-0753 | MEDIUM | 6.5 | 0.7% | Jan 23, 2024 | In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox ... |
| CVE-2024-0752 | MEDIUM | 6.5 | 0.4% | Jan 23, 2024 | A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This c... |
| CVE-2024-0749 | MEDIUM | 4.3 | 0.3% | Jan 23, 2024 | A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the addres... |
| CVE-2024-0748 | MEDIUM | 4.3 | 0.4% | Jan 23, 2024 | A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitra... |
| CVE-2024-0747 | MEDIUM | 6.5 | 0.6% | Jan 23, 2024 | When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overr... |
| CVE-2024-0746 | MEDIUM | 6.5 | 0.7% | Jan 23, 2024 | A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now