2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20477MEDIUM5.4A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac...
CVE-2024-20444MEDIUM5.5A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), co...
CVE-2024-20442MEDIUM5.4A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote ...
CVE-2024-20441MEDIUM6.5A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attac...
CVE-2024-20438MEDIUM5.4A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to...
CVE-2024-20385MEDIUM5.9A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated...
CVE-2024-9423MEDIUM5.3Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the pri...
CVE-2024-47804MEDIUM4.3If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#is...
CVE-2024-47803MEDIUM4.3Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated ...
CVE-2024-33210MEDIUM5.4A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker t...
CVE-2024-33209MEDIUM5.4FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "A...
CVE-2024-47611MEDIUM6.3XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinG...
CVE-2024-8038MEDIUM5.5Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection ...
CVE-2024-8037MEDIUM6.5Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the ...
CVE-2024-35294MEDIUM6.5An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ...
CVE-2024-8505MEDIUM5.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-8282MEDIUM5.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’...
CVE-2024-9378MEDIUM6.1The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter ...
CVE-2024-9344MEDIUM6.1The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaSc...
CVE-2024-9218MEDIUM6.1The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu...
CVE-2024-9225MEDIUM6.1The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-9222MEDIUM6.1The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-9210MEDIUM6.1The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_...
CVE-2024-9172MEDIUM5.4The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-8967MEDIUM5.4The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now