2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20350HIGH8.1A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, r...
CVE-2024-7421MEDIUM5.5An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers ...
CVE-2024-47078CRITICAL9.8Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an interne...
CVE-2024-46600MEDIUM4.7dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.p...
CVE-2024-46485MEDIUM6.3dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
CVE-2024-44825HIGH7.5Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attac...
CVE-2024-46461HIGH8VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be trigge...
CVE-2024-43990MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affe...
CVE-2024-43959HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testim...
CVE-2024-43237MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag...
CVE-2024-30128MEDIUM6.5HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask thei...
CVE-2024-22893HIGH7.5OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This ...
CVE-2024-22892HIGH7.5OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
CVE-2024-8316HIGH7.8In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an in...
CVE-2024-7679HIGH7.8In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible throu...
CVE-2024-7576CRITICAL9.8In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an in...
CVE-2024-7575CRITICAL9.8In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through im...
CVE-2024-6512MEDIUM6.5Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut...
CVE-2024-45613MEDIUM6.1CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Script...
CVE-2024-8546MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide...
CVE-2024-4657CRITICAL9.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft...
CVE-2024-6594HIGH7.5Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the ...
CVE-2024-6593CRITICAL9.1Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows ...
CVE-2024-6592CRITICAL9.1An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (ak...
CVE-2024-8858MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_set...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now