2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45967 | MEDIUM | 4.7 | 0.4% | Oct 1, 2024 | Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget. |
| CVE-2024-45408 | MEDIUM | 6.5 | 0.4% | Oct 1, 2024 | eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that c... |
| CVE-2024-44610 | MEDIUM | 5.6 | 1.0% | Oct 1, 2024 | PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via sh... |
| CVE-2024-41673 | HIGH | 7.1 | 0.4% | Oct 1, 2024 | Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XS... |
| CVE-2024-25661 | HIGH | 7.7 | 0.1% | Oct 1, 2024 | In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of ... |
| CVE-2024-25658 | MEDIUM | 6.5 | 0.2% | Oct 1, 2024 | Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (w... |
| CVE-2024-25632 | HIGH | 8.8 | 0.4% | Oct 1, 2024 | eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us... |
| CVE-2024-46276 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h. |
| CVE-2024-46274 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h. |
| CVE-2024-46267 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h. |
| CVE-2024-46264 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h. |
| CVE-2024-46263 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h. |
| CVE-2024-46261 | HIGH | 7.8 | 0.4% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h. |
| CVE-2024-46259 | HIGH | 7.8 | 0.5% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h. |
| CVE-2024-46258 | HIGH | 7.8 | 0.4% | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h. |
| CVE-2024-44744 | MEDIUM | 5.7 | 0.3% | Oct 1, 2024 | An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted bina... |
| CVE-2024-41276 | CRITICAL | 9.8 | 1.0% | Oct 1, 2024 | A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism... |
| CVE-2024-9405 | MEDIUM | 5.3 | 0.4% | Oct 1, 2024 | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting v... |
| CVE-2024-30132 | HIGH | 7.5 | 0.3% | Oct 1, 2024 | HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o... |
| CVE-2024-9118 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve... |
| CVE-2024-9060 | MEDIUM | 6.4 | 0.4% | Oct 1, 2024 | The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versio... |
| CVE-2024-9289 | CRITICAL | 9.8 | 0.6% | Oct 1, 2024 | The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version... |
| CVE-2024-9265 | CRITICAL | 9.8 | 0.6% | Oct 1, 2024 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i... |
| CVE-2024-9241 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-9228 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now