2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-41290HIGH8.1FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
CVE-2024-20491HIGH8.6A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech su...
CVE-2024-20490HIGH8.6A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orches...
CVE-2024-20470HIGH7.2A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ...
CVE-2024-20449HIGH8.8A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low...
CVE-2024-20448HIGH8.6A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manag...
CVE-2024-20432HIGH8.8A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticate...
CVE-2024-20393HIGH8.8A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ...
CVE-2024-20365HIGH7.2A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers cou...
CVE-2024-47807HIGH8.1Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of...
CVE-2024-47806HIGH8.1Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim ...
CVE-2024-47805HIGH7.5Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypte...
CVE-2024-44193HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attac...
CVE-2024-8885HIGH8.8A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and...
CVE-2024-7558HIGH8JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K...
CVE-2024-44030HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout M...
CVE-2024-44017HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board m...
CVE-2024-7315HIGH7.5The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that ...
CVE-2024-7855HIGH8.8The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2024-33662HIGH7.5Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-46084HIGH8Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
CVE-2024-46080HIGH8Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
CVE-2024-9341HIGH8.2A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa...
CVE-2024-42514HIGH8.1A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen...
CVE-2024-9403HIGH7.3Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now