2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41290 | HIGH | 8.1 | 0.4% | Oct 2, 2024 | FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component. |
| CVE-2024-20491 | HIGH | 8.6 | 0.3% | Oct 2, 2024 | A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech su... |
| CVE-2024-20490 | HIGH | 8.6 | 0.3% | Oct 2, 2024 | A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orches... |
| CVE-2024-20470 | HIGH | 7.2 | 0.6% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ... |
| CVE-2024-20449 | HIGH | 8.8 | 0.9% | Oct 2, 2024 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low... |
| CVE-2024-20448 | HIGH | 8.6 | 0.1% | Oct 2, 2024 | A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manag... |
| CVE-2024-20432 | HIGH | 8.8 | 1.1% | Oct 2, 2024 | A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticate... |
| CVE-2024-20393 | HIGH | 8.8 | 0.6% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN ... |
| CVE-2024-20365 | HIGH | 7.2 | 0.9% | Oct 2, 2024 | A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers cou... |
| CVE-2024-47807 | HIGH | 8.1 | 0.6% | Oct 2, 2024 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of... |
| CVE-2024-47806 | HIGH | 8.1 | 0.6% | Oct 2, 2024 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim ... |
| CVE-2024-47805 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypte... |
| CVE-2024-44193 | HIGH | 7.8 | 0.4% | Oct 2, 2024 | A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attac... |
| CVE-2024-8885 | HIGH | 8.8 | 0.1% | Oct 2, 2024 | A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and... |
| CVE-2024-7558 | HIGH | 8 | 0.5% | Oct 2, 2024 | JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K... |
| CVE-2024-44030 | HIGH | 7.2 | 0.6% | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout M... |
| CVE-2024-44017 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board m... |
| CVE-2024-7315 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that ... |
| CVE-2024-7855 | HIGH | 8.8 | 15.0% | Oct 2, 2024 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2024-33662 | HIGH | 7.5 | 0.3% | Oct 2, 2024 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. |
| CVE-2024-46084 | HIGH | 8 | 0.8% | Oct 1, 2024 | Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function. |
| CVE-2024-46080 | HIGH | 8 | 0.7% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function. |
| CVE-2024-9341 | HIGH | 8.2 | 1.0% | Oct 1, 2024 | A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa... |
| CVE-2024-42514 | HIGH | 8.1 | 0.4% | Oct 1, 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen... |
| CVE-2024-9403 | HIGH | 7.3 | 0.4% | Oct 1, 2024 | Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now