2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7107 | HIGH | 7.5 | 0.3% | Sep 26, 2024 | Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all... |
| CVE-2024-8704 | HIGH | 7.2 | 0.9% | Sep 26, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a... |
| CVE-2024-8126 | HIGH | 8.8 | 0.9% | Sep 26, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'... |
| CVE-2024-9199 | HIGH | 7.5 | 0.3% | Sep 26, 2024 | Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the ... |
| CVE-2024-47197 | HIGH | 7.5 | 0.8% | Sep 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M... |
| CVE-2024-0132 | HIGH | 8.3 | 36.5% | Sep 26, 2024 | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de... |
| CVE-2024-47045 | HIGH | 7.8 | 0.1% | Sep 26, 2024 | Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, ... |
| CVE-2024-47330 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i... |
| CVE-2024-8404 | HIGH | 7.8 | 0.4% | Sep 26, 2024 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print... |
| CVE-2024-47083 | HIGH | 7.5 | 1.5% | Sep 25, 2024 | Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior... |
| CVE-2024-47315 | HIGH | 8.8 | 0.2% | Sep 25, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= ... |
| CVE-2024-47305 | HIGH | 8.8 | 0.2% | Sep 25, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forge... |
| CVE-2024-47082 | HIGH | 8 | 0.2% | Sep 25, 2024 | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as de... |
| CVE-2024-46489 | HIGH | 8.8 | 0.9% | Sep 25, 2024 | A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr... |
| CVE-2024-45750 | HIGH | 7.3 | 0.5% | Sep 25, 2024 | An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and ol... |
| CVE-2024-8996 | HIGH | 7.8 | 0.3% | Sep 25, 2024 | Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from L... |
| CVE-2024-8975 | HIGH | 7.8 | 0.3% | Sep 25, 2024 | Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to... |
| CVE-2024-44678 | HIGH | 8 | 1.3% | Sep 25, 2024 | Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to exe... |
| CVE-2024-41708 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions vi... |
| CVE-2024-20480 | HIGH | 8.6 | 0.6% | Sep 25, 2024 | A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge... |
| CVE-2024-20467 | HIGH | 8.6 | 1.0% | Sep 25, 2024 | A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an ... |
| CVE-2024-20464 | HIGH | 8.6 | 0.6% | Sep 25, 2024 | A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthentica... |
| CVE-2024-20455 | HIGH | 8.6 | 0.7% | Sep 25, 2024 | A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Ci... |
| CVE-2024-20437 | HIGH | 8.8 | 0.3% | Sep 25, 2024 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at... |
| CVE-2024-20436 | HIGH | 7.5 | 0.9% | Sep 25, 2024 | A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now