2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0742 | MEDIUM | 4.3 | 0.6% | Jan 23, 2024 | It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to ... |
| CVE-2024-0741 | MEDIUM | 6.5 | 2.2% | Jan 23, 2024 | An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable cr... |
| CVE-2024-0703 | MEDIUM | 4.8 | 0.3% | Jan 23, 2024 | The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via stic... |
| CVE-2024-23183 | MEDIUM | 5.4 | 0.4% | Jan 23, 2024 | Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions... |
| CVE-2024-23181 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions... |
| CVE-2024-23851 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, ... |
| CVE-2024-23850 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and cra... |
| CVE-2024-23849 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS... |
| CVE-2024-23848 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-... |
| CVE-2024-0587 | MEDIUM | 6.1 | 0.4% | Jan 23, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2024-23224 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may... |
| CVE-2024-23223 | MEDIUM | 6.2 | 0.3% | Jan 23, 2024 | A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS So... |
| CVE-2024-23219 | MEDIUM | 6.2 | 0.3% | Jan 23, 2024 | The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Pro... |
| CVE-2024-23218 | MEDIUM | 5.9 | 1.0% | Jan 23, 2024 | A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. Thi... |
| CVE-2024-23215 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS... |
| CVE-2024-23207 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17... |
| CVE-2024-23206 | MEDIUM | 6.5 | 0.9% | Jan 23, 2024 | An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPad... |
| CVE-2024-23345 | MEDIUM | 5.4 | 0.4% | Jan 23, 2024 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot... |
| CVE-2024-23340 | MEDIUM | 5.3 | 0.7% | Jan 22, 2024 | @hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server h... |
| CVE-2024-23339 | MEDIUM | 6.5 | 1.0% | Jan 22, 2024 | hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0... |
| CVE-2024-23677 | MEDIUM | 5.3 | 0.4% | Jan 22, 2024 | In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applica... |
| CVE-2024-23675 | MEDIUM | 6.5 | 0.4% | Jan 22, 2024 | In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permission... |
| CVE-2024-0606 | MEDIUM | 6.1 | 0.3% | Jan 22, 2024 | An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascr... |
| CVE-2024-0430 | MEDIUM | 5.5 | 0.2% | Jan 22, 2024 | IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL... |
| CVE-2024-0782 | MEDIUM | 6.1 | 0.6% | Jan 22, 2024 | A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now