2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47305 | HIGH | 8.8 | 0.2% | Sep 25, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forge... |
| CVE-2024-47082 | HIGH | 8 | 0.2% | Sep 25, 2024 | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as de... |
| CVE-2024-46655 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in... |
| CVE-2024-46489 | HIGH | 8.8 | 0.9% | Sep 25, 2024 | A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr... |
| CVE-2024-46488 | MEDIUM | 5.5 | 0.4% | Sep 25, 2024 | sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability a... |
| CVE-2024-45750 | HIGH | 7.3 | 0.5% | Sep 25, 2024 | An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and ol... |
| CVE-2024-8996 | HIGH | 7.8 | 0.3% | Sep 25, 2024 | Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from L... |
| CVE-2024-8975 | HIGH | 7.8 | 0.3% | Sep 25, 2024 | Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to... |
| CVE-2024-44678 | HIGH | 8 | 1.3% | Sep 25, 2024 | Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to exe... |
| CVE-2024-41708 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions vi... |
| CVE-2024-41445 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the Read... |
| CVE-2024-20510 | CRITICAL | 9.3 | 0.3% | Sep 25, 2024 | A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could ... |
| CVE-2024-20508 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So... |
| CVE-2024-20496 | MEDIUM | 6.1 | 0.2% | Sep 25, 2024 | A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen... |
| CVE-2024-20480 | HIGH | 8.6 | 0.6% | Sep 25, 2024 | A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge... |
| CVE-2024-20475 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c... |
| CVE-2024-20467 | HIGH | 8.6 | 1.0% | Sep 25, 2024 | A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an ... |
| CVE-2024-20465 | MEDIUM | 5.8 | 0.4% | Sep 25, 2024 | A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet ... |
| CVE-2024-20464 | HIGH | 8.6 | 0.6% | Sep 25, 2024 | A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthentica... |
| CVE-2024-20455 | HIGH | 8.6 | 0.7% | Sep 25, 2024 | A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Ci... |
| CVE-2024-20437 | HIGH | 8.8 | 0.3% | Sep 25, 2024 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at... |
| CVE-2024-20436 | HIGH | 7.5 | 0.9% | Sep 25, 2024 | A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could ... |
| CVE-2024-20434 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service ... |
| CVE-2024-20433 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software coul... |
| CVE-2024-20414 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now