2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45723MEDIUM6.5The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The ran...
CVE-2024-45374MEDIUM6.5The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broad...
CVE-2024-45042MEDIUM4.4Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a...
CVE-2024-43814MEDIUM4.3The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates...
CVE-2024-43694MEDIUM6.5In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This a...
CVE-2024-43108MEDIUM6.5The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity...
CVE-2024-41931MEDIUM4.3The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broad...
CVE-2024-41722MEDIUM6.5In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GI...
CVE-2024-41715MEDIUM4.3The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message...
CVE-2024-8771MEDIUM4.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-7259MEDIUM4.9A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may ...
CVE-2024-46632MEDIUM4.3Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.
CVE-2024-45983MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The v...
CVE-2024-39319MEDIUM5.3aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024....
CVE-2024-9155MEDIUM4.3Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have no...
CVE-2024-9177MEDIUM5.4The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, them...
CVE-2024-46327MEDIUM5.7An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a dir...
CVE-2024-31899MEDIUM4.3IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user ...
CVE-2024-8633MEDIUM4.8The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ...
CVE-2024-8725MEDIUM5.4Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a...
CVE-2024-9198MEDIUM5.4Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X...
CVE-2024-9173MEDIUM5.4The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-9127MEDIUM5.4The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter i...
CVE-2024-9125MEDIUM5.4The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to...
CVE-2024-9117MEDIUM5.4The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now