2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7107HIGH7.5Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all...
CVE-2024-8704HIGH7.2The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a...
CVE-2024-8126HIGH8.8The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'...
CVE-2024-9199HIGH7.5Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the ...
CVE-2024-47197HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M...
CVE-2024-0132HIGH8.3NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de...
CVE-2024-47045HIGH7.8Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, ...
CVE-2024-47330HIGH8.8Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i...
CVE-2024-8404HIGH7.8An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print...
CVE-2024-47083HIGH7.5Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior...
CVE-2024-47315HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= ...
CVE-2024-47305HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forge...
CVE-2024-47082HIGH8Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as de...
CVE-2024-46489HIGH8.8A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr...
CVE-2024-45750HIGH7.3An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and ol...
CVE-2024-8996HIGH7.8Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from L...
CVE-2024-8975HIGH7.8Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to...
CVE-2024-44678HIGH8Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to exe...
CVE-2024-41708HIGH7.5An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions vi...
CVE-2024-20480HIGH8.6A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge...
CVE-2024-20467HIGH8.6A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an ...
CVE-2024-20464HIGH8.6A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthentica...
CVE-2024-20455HIGH8.6A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Ci...
CVE-2024-20437HIGH8.8A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at...
CVE-2024-20436HIGH7.5A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now