2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45838 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in c... |
| CVE-2024-45723 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The ran... |
| CVE-2024-45374 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broad... |
| CVE-2024-45042 | MEDIUM | 4.4 | 0.3% | Sep 26, 2024 | Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a... |
| CVE-2024-43814 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates... |
| CVE-2024-43694 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This a... |
| CVE-2024-43108 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity... |
| CVE-2024-41931 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broad... |
| CVE-2024-41722 | MEDIUM | 6.5 | 0.1% | Sep 26, 2024 | In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GI... |
| CVE-2024-41715 | MEDIUM | 4.3 | 0.1% | Sep 26, 2024 | The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message... |
| CVE-2024-39577 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of ... |
| CVE-2024-9203 | LOW | 2.5 | 0.1% | Sep 26, 2024 | A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. ... |
| CVE-2024-9166 | CRITICAL | 9.3 | 1.5% | Sep 26, 2024 | The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilit... |
| CVE-2024-46627 | CRITICAL | 9.1 | 3.9% | Sep 26, 2024 | Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests. |
| CVE-2024-45982 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user ... |
| CVE-2024-45981 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u... |
| CVE-2024-45980 | HIGH | 8.8 | 0.4% | Sep 26, 2024 | A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte... |
| CVE-2024-45979 | HIGH | 8.8 | 0.4% | Sep 26, 2024 | A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us... |
| CVE-2024-44860 | HIGH | 7.5 | 0.5% | Sep 26, 2024 | An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s... |
| CVE-2024-37125 | HIGH | 7.5 | 0.4% | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum... |
| CVE-2024-8771 | MEDIUM | 4.3 | 0.4% | Sep 26, 2024 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f... |
| CVE-2024-7259 | MEDIUM | 4.9 | 0.3% | Sep 26, 2024 | A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may ... |
| CVE-2024-46632 | MEDIUM | 4.3 | 0.4% | Sep 26, 2024 | Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. |
| CVE-2024-45983 | MEDIUM | 6.3 | 0.1% | Sep 26, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The v... |
| CVE-2024-43191 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now