2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46263 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h. |
| CVE-2024-46261 | HIGH | 7.8 | 0.4% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h. |
| CVE-2024-46259 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h. |
| CVE-2024-46258 | HIGH | 7.8 | 0.4% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h. |
| CVE-2024-30132 | HIGH | 7.5 | 0.3% | Oct 1, 2024 | HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o... |
| CVE-2024-9018 | HIGH | 8.8 | 0.5% | Oct 1, 2024 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k... |
| CVE-2024-9145 | HIGH | 7.1 | 0.8% | Oct 1, 2024 | Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver... |
| CVE-2024-8548 | HIGH | 8.1 | 0.4% | Oct 1, 2024 | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-7869 | HIGH | 7.2 | 0.4% | Oct 1, 2024 | The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i... |
| CVE-2024-7434 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via... |
| CVE-2024-7433 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi... |
| CVE-2024-7432 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi... |
| CVE-2024-21489 | HIGH | 8.2 | 0.6% | Oct 1, 2024 | Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to m... |
| CVE-2024-47295 | HIGH | 8.1 | 0.8% | Oct 1, 2024 | Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set ... |
| CVE-2024-8981 | HIGH | 7.1 | 0.5% | Oct 1, 2024 | The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-47560 | HIGH | 7.8 | 0.2% | Oct 1, 2024 | RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex... |
| CVE-2024-7675 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali... |
| CVE-2024-7674 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer O... |
| CVE-2024-7673 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Ove... |
| CVE-2024-7672 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bou... |
| CVE-2024-7671 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Writ... |
| CVE-2024-7670 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. ... |
| CVE-2024-28813 | HIGH | 8.4 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management applicatio... |
| CVE-2024-28812 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w... |
| CVE-2024-46511 | HIGH | 7.5 | 0.2% | Sep 30, 2024 | LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now