2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47836 | MEDIUM | 4.3 | 0.5% | Oct 16, 2024 | Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all... |
| CVE-2024-45796 | MEDIUM | 5.3 | 0.5% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-41128 | MEDIUM | 6.6 | 1.1% | Oct 16, 2024 | Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions ... |
| CVE-2024-9143 | MEDIUM | 4.3 | 6.0% | Oct 16, 2024 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial ... |
| CVE-2024-46606 | MEDIUM | 5.4 | 0.4% | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to ... |
| CVE-2024-46605 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to ... |
| CVE-2024-45072 | MEDIUM | 5.5 | 0.4% | Oct 16, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process... |
| CVE-2024-45071 | MEDIUM | 4.8 | 0.2% | Oct 16, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p... |
| CVE-2024-20512 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) c... |
| CVE-2024-20462 | MEDIUM | 5.5 | 0.2% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter fir... |
| CVE-2024-20461 | MEDIUM | 6 | 0.2% | Oct 16, 2024 | A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, ... |
| CVE-2024-20460 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20421 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20280 | MEDIUM | 6.3 | 0.1% | Oct 16, 2024 | A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file... |
| CVE-2024-10033 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. Th... |
| CVE-2024-49265 | MEDIUM | 5.4 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Book... |
| CVE-2024-29155 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device beco... |
| CVE-2024-49268 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkam... |
| CVE-2024-49267 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited ... |
| CVE-2024-49266 | MEDIUM | 5.9 | 0.3% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz W... |
| CVE-2024-48744 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Reco... |
| CVE-2024-47139 | MEDIUM | 6.8 | 0.5% | Oct 16, 2024 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that... |
| CVE-2024-49270 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart B... |
| CVE-2024-49258 | MEDIUM | 6.5 | 0.5% | Oct 16, 2024 | Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This is... |
| CVE-2024-49252 | MEDIUM | 5.3 | 0.4% | Oct 16, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now