2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37313HIGH7.5Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second fa...
CVE-2024-37312MEDIUM6.3user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an at...
CVE-2024-36656MEDIUM6.1In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (...
CVE-2024-34694HIGH8.1LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal ...
CVE-2024-34539CRITICAL9.4Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail ...
CVE-2024-33377HIGH8.1LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attacker...
CVE-2024-33375CRITICAL9.8LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
CVE-2024-33374CRITICAL9.8Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access th...
CVE-2024-23442MEDIUM6.1An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th...
CVE-2024-5731MEDIUM6.8A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to cont...
CVE-2024-5671CRITICAL9.8Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitra...
CVE-2024-37640HIGH8.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyG...
CVE-2024-37639HIGH8.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilt...
CVE-2024-37637CRITICAL9.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg...
CVE-2024-2024HIGH8.8The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ...
CVE-2024-2023MEDIUM4.3The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi...
CVE-2024-36459HIGH8.4A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for ...
CVE-2024-5685HIGH8.1Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes ...
CVE-2024-3912CRITICAL9.8Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can e...
CVE-2024-34012MEDIUM4.4Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage...
CVE-2024-2472CRITICAL9.1The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a...
CVE-2024-5996Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-4863MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-37182MEDIUM6.1Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows ...
CVE-2024-36287LOW3.3Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC rest...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now