2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45986 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs wh... |
| CVE-2024-7594 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip... |
| CVE-2024-47180 | HIGH | 8.8 | 1.0% | Sep 26, 2024 | Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-... |
| CVE-2024-47179 | HIGH | 8.8 | 0.7% | Sep 26, 2024 | RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po... |
| CVE-2024-46628 | CRITICAL | 9.8 | 11.0% | Sep 26, 2024 | Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbP... |
| CVE-2024-8118 | MEDIUM | 5.1 | 0.6% | Sep 26, 2024 | In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to writ... |
| CVE-2024-47174 | MEDIUM | 5.9 | 0.3% | Sep 26, 2024 | Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.2... |
| CVE-2024-47171 | MEDIUM | 4.3 | 0.5% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47170 | MEDIUM | 4.3 | 0.5% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47169 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47130 | MEDIUM | 6.5 | 0.2% | Sep 26, 2024 | The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group me... |
| CVE-2024-47129 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This ... |
| CVE-2024-47128 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast m... |
| CVE-2024-47127 | LOW | 3.1 | 0.1% | Sep 26, 2024 | In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Ca... |
| CVE-2024-47126 | HIGH | 8.8 | 0.2% | Sep 26, 2024 | The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random func... |
| CVE-2024-47125 | MEDIUM | 5.4 | 0.1% | Sep 26, 2024 | The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. ... |
| CVE-2024-47124 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in calls... |
| CVE-2024-47123 | LOW | 3.1 | 0.1% | Sep 26, 2024 | The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checkin... |
| CVE-2024-47122 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows... |
| CVE-2024-47121 | MEDIUM | 5.3 | 0.1% | Sep 26, 2024 | The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted e... |
| CVE-2024-47075 | MEDIUM | 6.1 | 0.3% | Sep 26, 2024 | LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerabil... |
| CVE-2024-45989 | MEDIUM | 4 | 0.3% | Sep 26, 2024 | Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Act... |
| CVE-2024-45987 | MEDIUM | 6.5 | 0.2% | Sep 26, 2024 | Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vul... |
| CVE-2024-45985 | MEDIUM | 4.7 | 0.3% | Sep 26, 2024 | A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allow... |
| CVE-2024-45984 | MEDIUM | 4.7 | 0.3% | Sep 26, 2024 | A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now