2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9400HIGH8.8A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe...
CVE-2024-9399HIGH7.5A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d...
CVE-2024-9396HIGH8.8It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj...
CVE-2024-9394HIGH7.5An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo...
CVE-2024-9393HIGH7.5An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js...
CVE-2024-47534HIGH8.2go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. Fo...
CVE-2024-25659HIGH7.2In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP s...
CVE-2024-41673HIGH7.1Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XS...
CVE-2024-25661HIGH7.7In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of ...
CVE-2024-25632HIGH8.8eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us...
CVE-2024-46276HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.
CVE-2024-46274HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
CVE-2024-46267HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
CVE-2024-46264HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
CVE-2024-46263HIGH7.8cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.
CVE-2024-46261HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
CVE-2024-46259HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
CVE-2024-46258HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
CVE-2024-30132HIGH7.5HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o...
CVE-2024-9018HIGH8.8The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k...
CVE-2024-9145HIGH7.1Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver...
CVE-2024-8548HIGH8.1The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-7869HIGH7.2The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i...
CVE-2024-7434HIGH8.8The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via...
CVE-2024-7433HIGH8.8The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now