2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45723 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The ran... |
| CVE-2024-45374 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broad... |
| CVE-2024-45042 | MEDIUM | 4.4 | 0.3% | Sep 26, 2024 | Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a... |
| CVE-2024-43814 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates... |
| CVE-2024-43694 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This a... |
| CVE-2024-43108 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity... |
| CVE-2024-41931 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broad... |
| CVE-2024-41722 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GI... |
| CVE-2024-41715 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message... |
| CVE-2024-8771 | MEDIUM | 4.3 | 0.4% | Sep 26, 2024 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f... |
| CVE-2024-7259 | MEDIUM | 4.9 | 0.3% | Sep 26, 2024 | A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may ... |
| CVE-2024-46632 | MEDIUM | 4.3 | 0.4% | Sep 26, 2024 | Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. |
| CVE-2024-45983 | MEDIUM | 6.3 | 0.1% | Sep 26, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The v... |
| CVE-2024-39319 | MEDIUM | 5.3 | 0.5% | Sep 26, 2024 | aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.... |
| CVE-2024-9155 | MEDIUM | 4.3 | 0.3% | Sep 26, 2024 | Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have no... |
| CVE-2024-9177 | MEDIUM | 5.4 | 0.4% | Sep 26, 2024 | The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, them... |
| CVE-2024-46327 | MEDIUM | 5.7 | 0.4% | Sep 26, 2024 | An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a dir... |
| CVE-2024-31899 | MEDIUM | 4.3 | 0.2% | Sep 26, 2024 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user ... |
| CVE-2024-8633 | MEDIUM | 4.8 | 0.3% | Sep 26, 2024 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-8725 | MEDIUM | 5.4 | 0.4% | Sep 26, 2024 | Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a... |
| CVE-2024-9198 | MEDIUM | 5.4 | 0.2% | Sep 26, 2024 | Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X... |
| CVE-2024-9173 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-9127 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter i... |
| CVE-2024-9125 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to... |
| CVE-2024-9117 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now