2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23663HIGH8.8An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 a...
CVE-2024-21759MEDIUM4.3An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7....
CVE-2024-6615HIGH8.8Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption a...
CVE-2024-6614MEDIUM4.3The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th...
CVE-2024-6613MEDIUM5.5The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th...
CVE-2024-6612MEDIUM5.3CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This cause...
CVE-2024-6611CRITICAL9.8A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec...
CVE-2024-6610MEDIUM4.3Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p...
CVE-2024-6609HIGH8.8When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerabilit...
CVE-2024-6608MEDIUM4.3It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewp...
CVE-2024-6607HIGH8.8It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notificati...
CVE-2024-6606HIGH8.2Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerab...
CVE-2024-6605HIGH8.8Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerabi...
CVE-2024-6604HIGH7.5Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidenc...
CVE-2024-6603HIGH7.4In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading ...
CVE-2024-6602CRITICAL9.8A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1...
CVE-2024-6601MEDIUM4.7A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerabilit...
CVE-2024-6600MEDIUM6.3Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allo...
CVE-2024-39697HIGH8.6phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumbe...
CVE-2024-38363HIGH8.5Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE v...
CVE-2024-6598MEDIUM6.5A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a...
CVE-2024-6527CRITICAL9.3SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disc...
CVE-2024-2177MEDIUM6.8A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 ...
CVE-2024-37952HIGH8.8Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects...
CVE-2024-37934CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Inject...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now