2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20477 | MEDIUM | 5.4 | 0.5% | Oct 2, 2024 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac... |
| CVE-2024-20444 | MEDIUM | 5.5 | 0.8% | Oct 2, 2024 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), co... |
| CVE-2024-20442 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote ... |
| CVE-2024-20441 | MEDIUM | 6.5 | 0.5% | Oct 2, 2024 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac... |
| CVE-2024-20438 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to... |
| CVE-2024-20385 | MEDIUM | 5.9 | 0.3% | Oct 2, 2024 | A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated... |
| CVE-2024-9423 | MEDIUM | 5.3 | 0.5% | Oct 2, 2024 | Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the pri... |
| CVE-2024-47804 | MEDIUM | 4.3 | 0.7% | Oct 2, 2024 | If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#is... |
| CVE-2024-47803 | MEDIUM | 4.3 | 0.8% | Oct 2, 2024 | Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated ... |
| CVE-2024-33210 | MEDIUM | 5.4 | 0.6% | Oct 2, 2024 | A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker t... |
| CVE-2024-33209 | MEDIUM | 5.4 | 0.8% | Oct 2, 2024 | FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "A... |
| CVE-2024-47611 | MEDIUM | 6.3 | 0.7% | Oct 2, 2024 | XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinG... |
| CVE-2024-8038 | MEDIUM | 5.5 | 0.2% | Oct 2, 2024 | Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection ... |
| CVE-2024-8037 | MEDIUM | 6.5 | 0.2% | Oct 2, 2024 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the ... |
| CVE-2024-35294 | MEDIUM | 6.5 | 0.4% | Oct 2, 2024 | An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ... |
| CVE-2024-8505 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-8282 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’... |
| CVE-2024-9378 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter ... |
| CVE-2024-9344 | MEDIUM | 6.1 | 0.3% | Oct 2, 2024 | The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaSc... |
| CVE-2024-9218 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu... |
| CVE-2024-9225 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-9222 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2024-9210 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_... |
| CVE-2024-9172 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2024-8967 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now