2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8405 | MEDIUM | 5.5 | 0.2% | Sep 26, 2024 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl... |
| CVE-2024-46655 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in... |
| CVE-2024-46488 | MEDIUM | 5.5 | 0.4% | Sep 25, 2024 | sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability a... |
| CVE-2024-41445 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the Read... |
| CVE-2024-20508 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So... |
| CVE-2024-20496 | MEDIUM | 6.1 | 0.2% | Sep 25, 2024 | A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen... |
| CVE-2024-20475 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c... |
| CVE-2024-20465 | MEDIUM | 5.8 | 0.4% | Sep 25, 2024 | A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet ... |
| CVE-2024-20434 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service ... |
| CVE-2024-20414 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re... |
| CVE-2024-7421 | MEDIUM | 5.5 | 0.2% | Sep 25, 2024 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers ... |
| CVE-2024-46600 | MEDIUM | 4.7 | 0.2% | Sep 25, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.p... |
| CVE-2024-46485 | MEDIUM | 6.3 | 0.2% | Sep 25, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate |
| CVE-2024-43990 | MEDIUM | 5.3 | 0.4% | Sep 25, 2024 | Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affe... |
| CVE-2024-43237 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag... |
| CVE-2024-30128 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask thei... |
| CVE-2024-6512 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut... |
| CVE-2024-45613 | MEDIUM | 6.1 | 0.5% | Sep 25, 2024 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Script... |
| CVE-2024-8546 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide... |
| CVE-2024-8858 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_set... |
| CVE-2024-9169 | MEDIUM | 4.8 | 0.3% | Sep 25, 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v... |
| CVE-2024-47303 | MEDIUM | 5.4 | 0.2% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ... |
| CVE-2024-40761 | MEDIUM | 5.3 | 0.7% | Sep 25, 2024 | Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using ... |
| CVE-2024-23454 | MEDIUM | 6.2 | 0.4% | Sep 25, 2024 | Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be pres... |
| CVE-2024-8910 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now