2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7558HIGH8JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K...
CVE-2024-44030HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout M...
CVE-2024-44017HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board m...
CVE-2024-7315HIGH7.5The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that ...
CVE-2024-7855HIGH8.8The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2024-33662HIGH7.5Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-46084HIGH8Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
CVE-2024-46080HIGH8Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
CVE-2024-9341HIGH8.2A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa...
CVE-2024-42514HIGH8.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen...
CVE-2024-9403HIGH7.3Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-9400HIGH8.8A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe...
CVE-2024-9399HIGH7.5A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d...
CVE-2024-9396HIGH8.8It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj...
CVE-2024-9394HIGH7.5An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo...
CVE-2024-9393HIGH7.5An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js...
CVE-2024-47534HIGH8.2go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. Fo...
CVE-2024-25659HIGH7.2In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP s...
CVE-2024-41673HIGH7.1Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XS...
CVE-2024-25661HIGH7.7In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of ...
CVE-2024-25632HIGH8.8eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us...
CVE-2024-46276HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.
CVE-2024-46274HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
CVE-2024-46267HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
CVE-2024-46264HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now