2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-46263HIGH7.8cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.
CVE-2024-46261HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
CVE-2024-46259HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
CVE-2024-46258HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
CVE-2024-30132HIGH7.5HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o...
CVE-2024-9018HIGH8.8The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k...
CVE-2024-9145HIGH7.1Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver...
CVE-2024-8548HIGH8.1The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-7869HIGH7.2The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i...
CVE-2024-7434HIGH8.8The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via...
CVE-2024-7433HIGH8.8The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi...
CVE-2024-7432HIGH8.8The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi...
CVE-2024-21489HIGH8.2Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to m...
CVE-2024-47295HIGH8.1Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set ...
CVE-2024-8981HIGH7.1The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-47560HIGH7.8RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex...
CVE-2024-7675HIGH7.8A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali...
CVE-2024-7674HIGH7.8A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer O...
CVE-2024-7673HIGH7.8A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Ove...
CVE-2024-7672HIGH7.8A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bou...
CVE-2024-7671HIGH7.8A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Writ...
CVE-2024-7670HIGH7.8A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. ...
CVE-2024-28813HIGH8.4An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management applicatio...
CVE-2024-28812HIGH8.8An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w...
CVE-2024-46511HIGH7.5LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now