2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20513 | MEDIUM | 5.3 | 0.5% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20509 | MEDIUM | 5.9 | 0.4% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20524 | MEDIUM | 6.8 | 0.5% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20523 | MEDIUM | 6.8 | 0.5% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20522 | MEDIUM | 6.8 | 0.5% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20517 | MEDIUM | 6.8 | 0.4% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20516 | MEDIUM | 6.8 | 0.4% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20515 | MEDIUM | 6.5 | 0.3% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2024-20492 | MEDIUM | 6.7 | 0.5% | Oct 2, 2024 | A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perfo... |
| CVE-2024-20477 | MEDIUM | 5.4 | 0.5% | Oct 2, 2024 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac... |
| CVE-2024-20444 | MEDIUM | 5.5 | 0.8% | Oct 2, 2024 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), co... |
| CVE-2024-20442 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote ... |
| CVE-2024-20441 | MEDIUM | 6.5 | 0.5% | Oct 2, 2024 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac... |
| CVE-2024-20438 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to... |
| CVE-2024-20385 | MEDIUM | 5.9 | 0.3% | Oct 2, 2024 | A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated... |
| CVE-2024-9423 | MEDIUM | 5.3 | 0.5% | Oct 2, 2024 | Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the pri... |
| CVE-2024-47804 | MEDIUM | 4.3 | 0.7% | Oct 2, 2024 | If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#is... |
| CVE-2024-47803 | MEDIUM | 4.3 | 0.8% | Oct 2, 2024 | Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated ... |
| CVE-2024-33210 | MEDIUM | 5.4 | 0.6% | Oct 2, 2024 | A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker t... |
| CVE-2024-33209 | MEDIUM | 5.4 | 0.8% | Oct 2, 2024 | FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "A... |
| CVE-2024-47611 | MEDIUM | 6.3 | 0.7% | Oct 2, 2024 | XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinG... |
| CVE-2024-8038 | MEDIUM | 5.5 | 0.2% | Oct 2, 2024 | Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection ... |
| CVE-2024-8037 | MEDIUM | 6.5 | 0.2% | Oct 2, 2024 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the ... |
| CVE-2024-35294 | MEDIUM | 6.5 | 0.4% | Oct 2, 2024 | An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ... |
| CVE-2024-8505 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now