2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8405MEDIUM5.5An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl...
CVE-2024-46655MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in...
CVE-2024-46488MEDIUM5.5sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability a...
CVE-2024-41445MEDIUM6.5Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the Read...
CVE-2024-20508MEDIUM6.5A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So...
CVE-2024-20496MEDIUM6.1A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen...
CVE-2024-20475MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2024-20465MEDIUM5.8A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet ...
CVE-2024-20434MEDIUM4.3A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service ...
CVE-2024-20414MEDIUM6.5A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re...
CVE-2024-7421MEDIUM5.5An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers ...
CVE-2024-46600MEDIUM4.7dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.p...
CVE-2024-46485MEDIUM6.3dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
CVE-2024-43990MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affe...
CVE-2024-43237MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag...
CVE-2024-30128MEDIUM6.5HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask thei...
CVE-2024-6512MEDIUM6.5Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut...
CVE-2024-45613MEDIUM6.1CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Script...
CVE-2024-8546MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide...
CVE-2024-8858MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_set...
CVE-2024-9169MEDIUM4.8The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v...
CVE-2024-47303MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ...
CVE-2024-40761MEDIUM5.3Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using ...
CVE-2024-23454MEDIUM6.2Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be pres...
CVE-2024-8910MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now