2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47124MEDIUM6.5The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in calls...
CVE-2024-47122MEDIUM6.5In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows...
CVE-2024-47121MEDIUM5.3The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted e...
CVE-2024-47075MEDIUM6.1LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerabil...
CVE-2024-45989MEDIUM4Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Act...
CVE-2024-45987MEDIUM6.5Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vul...
CVE-2024-45985MEDIUM4.7A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allow...
CVE-2024-45984MEDIUM4.7A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an a...
CVE-2024-45838MEDIUM4.3The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in c...
CVE-2024-45723MEDIUM6.5The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The ran...
CVE-2024-45374MEDIUM6.5The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broad...
CVE-2024-45042MEDIUM4.4Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a...
CVE-2024-43814MEDIUM4.3The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates...
CVE-2024-43694MEDIUM6.5In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This a...
CVE-2024-43108MEDIUM6.5The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity...
CVE-2024-41931MEDIUM4.3The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broad...
CVE-2024-41722MEDIUM6.5In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GI...
CVE-2024-41715MEDIUM4.3The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message...
CVE-2024-8771MEDIUM4.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-7259MEDIUM4.9A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may ...
CVE-2024-46632MEDIUM4.3Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.
CVE-2024-45983MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The v...
CVE-2024-39319MEDIUM5.3aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024....
CVE-2024-9155MEDIUM4.3Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have no...
CVE-2024-9177MEDIUM5.4The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, them...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now