2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20459HIGH7.2A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter fir...
CVE-2024-20458HIGH8.2A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...
CVE-2024-20421MEDIUM6.5A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...
CVE-2024-20420HIGH8.8A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...
CVE-2024-20280MEDIUM6.3A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file...
CVE-2024-10033MEDIUM6.1A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. Th...
CVE-2024-49265MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Book...
CVE-2024-29155MEDIUM4.3On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device beco...
CVE-2024-9348HIGH8.9Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
CVE-2024-49268MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkam...
CVE-2024-49267MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited ...
CVE-2024-49266MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz W...
CVE-2024-48744MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Reco...
CVE-2024-47139MEDIUM6.8A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that...
CVE-2024-45844HIGH8.6BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdow...
CVE-2024-9893CRITICAL9.8The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and incl...
CVE-2024-49270MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart B...
CVE-2024-49260CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery ...
CVE-2024-49258MEDIUM6.5Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This is...
CVE-2024-49254CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code...
CVE-2024-49253HIGH8.6Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal....
CVE-2024-49252MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi...
CVE-2024-49251HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-49245HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image ...
CVE-2024-49242CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now