2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23663 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 a... |
| CVE-2024-21759 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.... |
| CVE-2024-6615 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption a... |
| CVE-2024-6614 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th... |
| CVE-2024-6613 | MEDIUM | 5.5 | 0.2% | Jul 9, 2024 | The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th... |
| CVE-2024-6612 | MEDIUM | 5.3 | 0.5% | Jul 9, 2024 | CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This cause... |
| CVE-2024-6611 | CRITICAL | 9.8 | 0.7% | Jul 9, 2024 | A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec... |
| CVE-2024-6610 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p... |
| CVE-2024-6609 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerabilit... |
| CVE-2024-6608 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewp... |
| CVE-2024-6607 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notificati... |
| CVE-2024-6606 | HIGH | 8.2 | 0.4% | Jul 9, 2024 | Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerab... |
| CVE-2024-6605 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerabi... |
| CVE-2024-6604 | HIGH | 7.5 | 0.5% | Jul 9, 2024 | Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidenc... |
| CVE-2024-6603 | HIGH | 7.4 | 0.5% | Jul 9, 2024 | In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading ... |
| CVE-2024-6602 | CRITICAL | 9.8 | 1.0% | Jul 9, 2024 | A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1... |
| CVE-2024-6601 | MEDIUM | 4.7 | 0.4% | Jul 9, 2024 | A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerabilit... |
| CVE-2024-6600 | MEDIUM | 6.3 | 0.4% | Jul 9, 2024 | Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allo... |
| CVE-2024-39697 | HIGH | 8.6 | 0.7% | Jul 9, 2024 | phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumbe... |
| CVE-2024-38363 | HIGH | 8.5 | 0.7% | Jul 9, 2024 | Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE v... |
| CVE-2024-6598 | MEDIUM | 6.5 | 0.5% | Jul 9, 2024 | A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a... |
| CVE-2024-6527 | CRITICAL | 9.3 | 0.6% | Jul 9, 2024 | SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disc... |
| CVE-2024-2177 | MEDIUM | 6.8 | 0.7% | Jul 9, 2024 | A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 ... |
| CVE-2024-37952 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects... |
| CVE-2024-37934 | CRITICAL | 9.8 | 0.5% | Jul 9, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Inject... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now