2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20514MEDIUM5.4A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2024-20511MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2024-20507MEDIUM6.5A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to vi...
CVE-2024-20504MEDIUM5.4A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, ...
CVE-2024-20487MEDIUM5.4A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond...
CVE-2024-20476MEDIUM4.9A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypa...
CVE-2024-20457MEDIUM6.5A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM I...
CVE-2024-20445MEDIUM5.3A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon...
CVE-2024-20371MEDIUM5.3A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticat...
CVE-2024-10318MEDIUM5.4A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not chec...
CVE-2024-35146MEDIUM5.4IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This ...
CVE-2024-10916MEDIUM5.3A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 202410...
CVE-2024-10186MEDIUM5.4The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode i...
CVE-2024-8323MEDIUM5.4The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-10168MEDIUM5.4The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Store...
CVE-2024-10715MEDIUM5.4The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map b...
CVE-2024-9902MEDIUM6.3A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace...
CVE-2024-9681MEDIUM6.5When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it...
CVE-2024-52043MEDIUM5.3Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavatio...
CVE-2024-6626MEDIUM5.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized...
CVE-2024-10543MEDIUM4.3The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-10535MEDIUM5.3The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-9934MEDIUM6.1The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back...
CVE-2024-7879MEDIUM4.8The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-49409MEDIUM6.7Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now