2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22380MEDIUM5.5Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development ...
CVE-2024-21796MEDIUM5.5Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creat...
CVE-2024-21765MEDIUM5.5Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 a...
CVE-2024-23638MEDIUM6.5Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable ...
CVE-2024-23633MEDIUM6.1Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote w...
CVE-2024-23453MEDIUM5.5Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retri...
CVE-2024-0814MEDIUM6.5Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof...
CVE-2024-0811MEDIUM4.3Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced...
CVE-2024-0810MEDIUM4.3Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a ...
CVE-2024-0809MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Aut...
CVE-2024-0805MEDIUM4.3Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform d...
CVE-2024-22497MEDIUM6.1Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run a...
CVE-2024-23341MEDIUM6.1TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, a...
CVE-2024-23330MEDIUM5.3Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is...
CVE-2024-22417MEDIUM6.1Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` ...
CVE-2024-22204MEDIUM5.3Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when...
CVE-2024-22496MEDIUM6.1Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login ...
CVE-2024-22490MEDIUM6.1Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword ...
CVE-2024-0754MEDIUM6.5Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
CVE-2024-0753MEDIUM6.5In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox ...
CVE-2024-0752MEDIUM6.5A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This c...
CVE-2024-0749MEDIUM4.3A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the addres...
CVE-2024-0748MEDIUM4.3A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitra...
CVE-2024-0747MEDIUM6.5When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overr...
CVE-2024-0746MEDIUM6.5A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now