2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45986MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs wh...
CVE-2024-7594HIGH8.8Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip...
CVE-2024-47180HIGH8.8Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-...
CVE-2024-47179HIGH8.8RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po...
CVE-2024-46628CRITICAL9.8Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbP...
CVE-2024-8118MEDIUM5.1In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to writ...
CVE-2024-47174MEDIUM5.9Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.2...
CVE-2024-47171MEDIUM4.3Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47170MEDIUM4.3Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47169HIGH8.8Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47130MEDIUM6.5The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group me...
CVE-2024-47129MEDIUM4.3The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This ...
CVE-2024-47128MEDIUM4.3The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast m...
CVE-2024-47127LOW3.1In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Ca...
CVE-2024-47126HIGH8.8The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random func...
CVE-2024-47125MEDIUM5.4The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. ...
CVE-2024-47124MEDIUM6.5The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in calls...
CVE-2024-47123LOW3.1The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checkin...
CVE-2024-47122MEDIUM6.5In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows...
CVE-2024-47121MEDIUM5.3The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted e...
CVE-2024-47075MEDIUM6.1LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerabil...
CVE-2024-45989MEDIUM4Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Act...
CVE-2024-45987MEDIUM6.5Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vul...
CVE-2024-45985MEDIUM4.7A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allow...
CVE-2024-45984MEDIUM4.7A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now