2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47305HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forge...
CVE-2024-47082HIGH8Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as de...
CVE-2024-46655MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in...
CVE-2024-46489HIGH8.8A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr...
CVE-2024-46488MEDIUM5.5sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability a...
CVE-2024-45750HIGH7.3An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and ol...
CVE-2024-8996HIGH7.8Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from L...
CVE-2024-8975HIGH7.8Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to...
CVE-2024-44678HIGH8Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to exe...
CVE-2024-41708HIGH7.5An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions vi...
CVE-2024-41445MEDIUM6.5Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the Read...
CVE-2024-20510CRITICAL9.3A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could ...
CVE-2024-20508MEDIUM6.5A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So...
CVE-2024-20496MEDIUM6.1A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen...
CVE-2024-20480HIGH8.6A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge...
CVE-2024-20475MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2024-20467HIGH8.6A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an ...
CVE-2024-20465MEDIUM5.8A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet ...
CVE-2024-20464HIGH8.6A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthentica...
CVE-2024-20455HIGH8.6A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Ci...
CVE-2024-20437HIGH8.8A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at...
CVE-2024-20436HIGH7.5A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could ...
CVE-2024-20434MEDIUM4.3A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service ...
CVE-2024-20433HIGH7.5A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software coul...
CVE-2024-20414MEDIUM6.5A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now