2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20459 | HIGH | 7.2 | 0.7% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter fir... |
| CVE-2024-20458 | HIGH | 8.2 | 0.7% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20421 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20420 | HIGH | 8.8 | 0.4% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20280 | MEDIUM | 6.3 | 0.1% | Oct 16, 2024 | A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file... |
| CVE-2024-10033 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. Th... |
| CVE-2024-49265 | MEDIUM | 5.4 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Book... |
| CVE-2024-29155 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device beco... |
| CVE-2024-9348 | HIGH | 8.9 | 0.5% | Oct 16, 2024 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view. |
| CVE-2024-49268 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkam... |
| CVE-2024-49267 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited ... |
| CVE-2024-49266 | MEDIUM | 5.9 | 0.3% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz W... |
| CVE-2024-48744 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Reco... |
| CVE-2024-47139 | MEDIUM | 6.8 | 0.5% | Oct 16, 2024 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that... |
| CVE-2024-45844 | HIGH | 8.6 | 10.6% | Oct 16, 2024 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdow... |
| CVE-2024-9893 | CRITICAL | 9.8 | 0.6% | Oct 16, 2024 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and incl... |
| CVE-2024-49270 | MEDIUM | 6.5 | 0.2% | Oct 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart B... |
| CVE-2024-49260 | CRITICAL | 9.9 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery ... |
| CVE-2024-49258 | MEDIUM | 6.5 | 0.5% | Oct 16, 2024 | Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This is... |
| CVE-2024-49254 | CRITICAL | 10 | 0.5% | Oct 16, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code... |
| CVE-2024-49253 | HIGH | 8.6 | 0.6% | Oct 16, 2024 | Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.... |
| CVE-2024-49252 | MEDIUM | 5.3 | 0.4% | Oct 16, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi... |
| CVE-2024-49251 | HIGH | 7.5 | 0.6% | Oct 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49245 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image ... |
| CVE-2024-49242 | CRITICAL | 10 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now