2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47136 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2024-47135 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming S... |
| CVE-2024-47134 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)... |
| CVE-2024-28888 | HIGH | 8.8 | 1.9% | Oct 2, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A special... |
| CVE-2024-8733 | HIGH | 8 | 0.2% | Oct 2, 2024 | A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow... |
| CVE-2024-20502 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20501 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate... |
| CVE-2024-20500 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20499 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate... |
| CVE-2024-20498 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate... |
| CVE-2024-46626 | HIGH | 8.8 | 0.9% | Oct 2, 2024 | OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload. |
| CVE-2024-41290 | HIGH | 8.1 | 0.4% | Oct 2, 2024 | FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component. |
| CVE-2024-20491 | HIGH | 8.6 | 0.3% | Oct 2, 2024 | A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech su... |
| CVE-2024-20490 | HIGH | 8.6 | 0.3% | Oct 2, 2024 | A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orches... |
| CVE-2024-20470 | HIGH | 7.2 | 0.6% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ... |
| CVE-2024-20449 | HIGH | 8.8 | 0.9% | Oct 2, 2024 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low... |
| CVE-2024-20448 | HIGH | 8.6 | 0.1% | Oct 2, 2024 | A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manag... |
| CVE-2024-20432 | HIGH | 8.8 | 1.1% | Oct 2, 2024 | A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticate... |
| CVE-2024-20393 | HIGH | 8.8 | 0.6% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ... |
| CVE-2024-20365 | HIGH | 7.2 | 0.9% | Oct 2, 2024 | A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers cou... |
| CVE-2024-47807 | HIGH | 8.1 | 0.6% | Oct 2, 2024 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of... |
| CVE-2024-47806 | HIGH | 8.1 | 0.6% | Oct 2, 2024 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim ... |
| CVE-2024-47805 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypte... |
| CVE-2024-44193 | HIGH | 7.8 | 0.4% | Oct 2, 2024 | A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attac... |
| CVE-2024-8885 | HIGH | 8.8 | 0.1% | Oct 2, 2024 | A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now