2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20512 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) c... |
| CVE-2024-20462 | MEDIUM | 5.5 | 0.2% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter fir... |
| CVE-2024-20461 | MEDIUM | 6 | 0.2% | Oct 16, 2024 | A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, ... |
| CVE-2024-20460 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20421 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20280 | MEDIUM | 6.3 | 0.1% | Oct 16, 2024 | A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file... |
| CVE-2024-10033 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. Th... |
| CVE-2024-49265 | MEDIUM | 5.4 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Book... |
| CVE-2024-29155 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device beco... |
| CVE-2024-49268 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkam... |
| CVE-2024-49267 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited ... |
| CVE-2024-49266 | MEDIUM | 5.9 | 0.3% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz W... |
| CVE-2024-48744 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Reco... |
| CVE-2024-47139 | MEDIUM | 6.8 | 0.5% | Oct 16, 2024 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that... |
| CVE-2024-49270 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart B... |
| CVE-2024-49258 | MEDIUM | 6.5 | 0.5% | Oct 16, 2024 | Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This is... |
| CVE-2024-49252 | MEDIUM | 5.3 | 0.4% | Oct 16, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi... |
| CVE-2024-22034 | MEDIUM | 5.5 | 0.2% | Oct 16, 2024 | Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker t... |
| CVE-2024-22033 | MEDIUM | 6.3 | 0.9% | Oct 16, 2024 | The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide... |
| CVE-2024-6380 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-8921 | MEDIUM | 6.4 | 0.4% | Oct 16, 2024 | The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i... |
| CVE-2024-9444 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up... |
| CVE-2024-9540 | MEDIUM | 4.3 | 0.4% | Oct 16, 2024 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2024-45715 | MEDIUM | 5.2 | 0.3% | Oct 16, 2024 | The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to exis... |
| CVE-2024-45714 | MEDIUM | 4.1 | 0.8% | Oct 16, 2024 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now