2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7558 | HIGH | 8 | 0.5% | Oct 2, 2024 | JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K... |
| CVE-2024-44030 | HIGH | 7.2 | 0.6% | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout M... |
| CVE-2024-44017 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board m... |
| CVE-2024-7315 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that ... |
| CVE-2024-7855 | HIGH | 8.8 | 15.0% | Oct 2, 2024 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2024-33662 | HIGH | 7.5 | 0.3% | Oct 2, 2024 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. |
| CVE-2024-46084 | HIGH | 8 | 0.8% | Oct 1, 2024 | Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function. |
| CVE-2024-46080 | HIGH | 8 | 0.7% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function. |
| CVE-2024-9341 | HIGH | 8.2 | 1.0% | Oct 1, 2024 | A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa... |
| CVE-2024-42514 | HIGH | 8.1 | 0.4% | Oct 1, 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen... |
| CVE-2024-9403 | HIGH | 7.3 | 0.4% | Oct 1, 2024 | Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-9400 | HIGH | 8.8 | 0.5% | Oct 1, 2024 | A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe... |
| CVE-2024-9399 | HIGH | 7.5 | 0.5% | Oct 1, 2024 | A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d... |
| CVE-2024-9396 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj... |
| CVE-2024-9394 | HIGH | 7.5 | 0.5% | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo... |
| CVE-2024-9393 | HIGH | 7.5 | 0.4% | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js... |
| CVE-2024-47534 | HIGH | 8.2 | 0.5% | Oct 1, 2024 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. Fo... |
| CVE-2024-25659 | HIGH | 7.2 | 0.7% | Oct 1, 2024 | In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP s... |
| CVE-2024-41673 | HIGH | 7.1 | 0.4% | Oct 1, 2024 | Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XS... |
| CVE-2024-25661 | HIGH | 7.7 | 0.1% | Oct 1, 2024 | In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of ... |
| CVE-2024-25632 | HIGH | 8.8 | 0.4% | Oct 1, 2024 | eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us... |
| CVE-2024-46276 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h. |
| CVE-2024-46274 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h. |
| CVE-2024-46267 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h. |
| CVE-2024-46264 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now