2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45838MEDIUM4.3The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in c...
CVE-2024-45723MEDIUM6.5The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The ran...
CVE-2024-45374MEDIUM6.5The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broad...
CVE-2024-45042MEDIUM4.4Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a...
CVE-2024-43814MEDIUM4.3The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates...
CVE-2024-43694MEDIUM6.5In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This a...
CVE-2024-43108MEDIUM6.5The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity...
CVE-2024-41931MEDIUM4.3The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broad...
CVE-2024-41722MEDIUM6.5In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GI...
CVE-2024-41715MEDIUM4.3The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message...
CVE-2024-39577HIGH8.8Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of ...
CVE-2024-9203LOW2.5A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. ...
CVE-2024-9166CRITICAL9.3The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilit...
CVE-2024-46627CRITICAL9.1Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
CVE-2024-45982HIGH8.8A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user ...
CVE-2024-45981HIGH8.8A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u...
CVE-2024-45980HIGH8.8A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte...
CVE-2024-45979HIGH8.8A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us...
CVE-2024-44860HIGH7.5An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s...
CVE-2024-37125HIGH7.5Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum...
CVE-2024-8771MEDIUM4.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-7259MEDIUM4.9A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may ...
CVE-2024-46632MEDIUM4.3Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.
CVE-2024-45983MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The v...
CVE-2024-43191HIGH8.8IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now