2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20514 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2024-20511 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2024-20507 | MEDIUM | 6.5 | 0.4% | Nov 6, 2024 | A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to vi... |
| CVE-2024-20504 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, ... |
| CVE-2024-20487 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond... |
| CVE-2024-20476 | MEDIUM | 4.9 | 0.3% | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypa... |
| CVE-2024-20457 | MEDIUM | 6.5 | 0.4% | Nov 6, 2024 | A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM I... |
| CVE-2024-20445 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon... |
| CVE-2024-20371 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticat... |
| CVE-2024-10318 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not chec... |
| CVE-2024-35146 | MEDIUM | 5.4 | 0.2% | Nov 6, 2024 | IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This ... |
| CVE-2024-10916 | MEDIUM | 5.3 | 1.5% | Nov 6, 2024 | A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 202410... |
| CVE-2024-10186 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode i... |
| CVE-2024-8323 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-10168 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Store... |
| CVE-2024-10715 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map b... |
| CVE-2024-9902 | MEDIUM | 6.3 | 0.2% | Nov 6, 2024 | A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace... |
| CVE-2024-9681 | MEDIUM | 6.5 | 2.0% | Nov 6, 2024 | When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it... |
| CVE-2024-52043 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavatio... |
| CVE-2024-6626 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized... |
| CVE-2024-10543 | MEDIUM | 4.3 | 0.3% | Nov 6, 2024 | The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2024-10535 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-9934 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back... |
| CVE-2024-7879 | MEDIUM | 4.8 | 0.3% | Nov 6, 2024 | The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-49409 | MEDIUM | 6.7 | 0.1% | Nov 6, 2024 | Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now