2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45967MEDIUM4.7Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
CVE-2024-45408MEDIUM6.5eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that c...
CVE-2024-44610MEDIUM5.6PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via sh...
CVE-2024-41673HIGH7.1Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XS...
CVE-2024-25661HIGH7.7In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of ...
CVE-2024-25658MEDIUM6.5Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (w...
CVE-2024-25632HIGH8.8eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us...
CVE-2024-46276HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.
CVE-2024-46274HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
CVE-2024-46267HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
CVE-2024-46264HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
CVE-2024-46263HIGH7.8cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.
CVE-2024-46261HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
CVE-2024-46259HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
CVE-2024-46258HIGH7.8cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
CVE-2024-44744MEDIUM5.7An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted bina...
CVE-2024-41276CRITICAL9.8A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism...
CVE-2024-9405MEDIUM5.3An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting v...
CVE-2024-30132HIGH7.5HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o...
CVE-2024-9118MEDIUM6.4The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve...
CVE-2024-9060MEDIUM6.4The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versio...
CVE-2024-9289CRITICAL9.8The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version...
CVE-2024-9265CRITICAL9.8The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i...
CVE-2024-9241MEDIUM6.1The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-9228MEDIUM6.1The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now