2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20350 | HIGH | 8.1 | 0.4% | Sep 25, 2024 | A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, r... |
| CVE-2024-7421 | MEDIUM | 5.5 | 0.2% | Sep 25, 2024 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers ... |
| CVE-2024-47078 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an interne... |
| CVE-2024-46600 | MEDIUM | 4.7 | 0.2% | Sep 25, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.p... |
| CVE-2024-46485 | MEDIUM | 6.3 | 0.2% | Sep 25, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate |
| CVE-2024-44825 | HIGH | 7.5 | 0.9% | Sep 25, 2024 | Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attac... |
| CVE-2024-46461 | HIGH | 8 | 0.6% | Sep 25, 2024 | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be trigge... |
| CVE-2024-43990 | MEDIUM | 5.3 | 0.4% | Sep 25, 2024 | Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affe... |
| CVE-2024-43959 | HIGH | 7.1 | 0.3% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testim... |
| CVE-2024-43237 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag... |
| CVE-2024-30128 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask thei... |
| CVE-2024-22893 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This ... |
| CVE-2024-22892 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords. |
| CVE-2024-8316 | HIGH | 7.8 | 0.2% | Sep 25, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an in... |
| CVE-2024-7679 | HIGH | 7.8 | 0.7% | Sep 25, 2024 | In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible throu... |
| CVE-2024-7576 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an in... |
| CVE-2024-7575 | CRITICAL | 9.8 | 0.7% | Sep 25, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through im... |
| CVE-2024-6512 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut... |
| CVE-2024-45613 | MEDIUM | 6.1 | 0.5% | Sep 25, 2024 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Script... |
| CVE-2024-8546 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide... |
| CVE-2024-4657 | CRITICAL | 9.3 | 0.4% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2024-6594 | HIGH | 7.5 | 0.5% | Sep 25, 2024 | Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the ... |
| CVE-2024-6593 | CRITICAL | 9.1 | 0.5% | Sep 25, 2024 | Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows ... |
| CVE-2024-6592 | CRITICAL | 9.1 | 1.0% | Sep 25, 2024 | An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (ak... |
| CVE-2024-8858 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_set... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now