2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9400 | HIGH | 8.8 | 0.5% | Oct 1, 2024 | A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe... |
| CVE-2024-9399 | HIGH | 7.5 | 0.5% | Oct 1, 2024 | A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d... |
| CVE-2024-9396 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj... |
| CVE-2024-9394 | HIGH | 7.5 | 0.5% | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo... |
| CVE-2024-9393 | HIGH | 7.5 | 0.4% | Oct 1, 2024 | An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js... |
| CVE-2024-47534 | HIGH | 8.2 | 0.5% | Oct 1, 2024 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. Fo... |
| CVE-2024-25659 | HIGH | 7.2 | 0.7% | Oct 1, 2024 | In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP s... |
| CVE-2024-41673 | HIGH | 7.1 | 0.4% | Oct 1, 2024 | Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XS... |
| CVE-2024-25661 | HIGH | 7.7 | 0.1% | Oct 1, 2024 | In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of ... |
| CVE-2024-25632 | HIGH | 8.8 | 0.4% | Oct 1, 2024 | eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us... |
| CVE-2024-46276 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h. |
| CVE-2024-46274 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h. |
| CVE-2024-46267 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h. |
| CVE-2024-46264 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h. |
| CVE-2024-46263 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h. |
| CVE-2024-46261 | HIGH | 7.8 | 0.4% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h. |
| CVE-2024-46259 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h. |
| CVE-2024-46258 | HIGH | 7.8 | 0.4% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h. |
| CVE-2024-30132 | HIGH | 7.5 | 0.3% | Oct 1, 2024 | HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o... |
| CVE-2024-9018 | HIGH | 8.8 | 0.5% | Oct 1, 2024 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k... |
| CVE-2024-9145 | HIGH | 7.1 | 0.8% | Oct 1, 2024 | Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver... |
| CVE-2024-8548 | HIGH | 8.1 | 0.4% | Oct 1, 2024 | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-7869 | HIGH | 7.2 | 0.4% | Oct 1, 2024 | The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i... |
| CVE-2024-7434 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via... |
| CVE-2024-7433 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now