2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8991 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and o... |
| CVE-2024-8681 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Medi... |
| CVE-2024-8965 | MEDIUM | 5.4 | 0.3% | Sep 27, 2024 | The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom ... |
| CVE-2024-7011 | MEDIUM | 6.5 | 0.3% | Sep 27, 2024 | Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, ... |
| CVE-2024-8974 | MEDIUM | 4.3 | 0.3% | Sep 26, 2024 | Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 ... |
| CVE-2024-4099 | MEDIUM | 5.3 | 0.3% | Sep 26, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to ... |
| CVE-2024-47176 | MEDIUM | 5.3 | 62.3% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality inclu... |
| CVE-2024-45986 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs wh... |
| CVE-2024-8118 | MEDIUM | 5.1 | 0.6% | Sep 26, 2024 | In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to writ... |
| CVE-2024-47174 | MEDIUM | 5.9 | 0.3% | Sep 26, 2024 | Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.2... |
| CVE-2024-47171 | MEDIUM | 4.3 | 0.5% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47170 | MEDIUM | 4.3 | 0.5% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47130 | MEDIUM | 6.5 | 0.2% | Sep 26, 2024 | The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group me... |
| CVE-2024-47129 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This ... |
| CVE-2024-47128 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast m... |
| CVE-2024-47125 | MEDIUM | 5.4 | 0.1% | Sep 26, 2024 | The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. ... |
| CVE-2024-47124 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in calls... |
| CVE-2024-47122 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows... |
| CVE-2024-47121 | MEDIUM | 5.3 | 0.1% | Sep 26, 2024 | The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted e... |
| CVE-2024-47075 | MEDIUM | 6.1 | 0.3% | Sep 26, 2024 | LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerabil... |
| CVE-2024-45989 | MEDIUM | 4 | 0.3% | Sep 26, 2024 | Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Act... |
| CVE-2024-45987 | MEDIUM | 6.5 | 0.2% | Sep 26, 2024 | Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vul... |
| CVE-2024-45985 | MEDIUM | 4.7 | 0.3% | Sep 26, 2024 | A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allow... |
| CVE-2024-45984 | MEDIUM | 4.7 | 0.3% | Sep 26, 2024 | A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an a... |
| CVE-2024-45838 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now