2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52602 | MEDIUM | 5.3 | 0.6% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) i... |
| CVE-2024-36403 | HIGH | 7.5 | 0.7% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ... |
| CVE-2024-36402 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ... |
| CVE-2024-57684 | CRITICAL | 9.8 | 14.4% | Jan 16, 2025 | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at... |
| CVE-2024-57683 | MEDIUM | 4.3 | 0.5% | Jan 16, 2025 | An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenti... |
| CVE-2024-57682 | MEDIUM | 6.5 | 0.5% | Jan 16, 2025 | An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows u... |
| CVE-2024-57681 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a... |
| CVE-2024-57680 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth... |
| CVE-2024-57679 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthe... |
| CVE-2024-57678 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated ... |
| CVE-2024-57677 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a... |
| CVE-2024-57676 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth... |
| CVE-2024-52594 | MEDIUM | 4.3 | 0.3% | Jan 16, 2025 | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery,... |
| CVE-2024-57776 | MEDIUM | 4.6 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-57775 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?ins... |
| CVE-2024-57774 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.... |
| CVE-2024-57773 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57772 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57771 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-57770 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr... |
| CVE-2024-57769 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa... |
| CVE-2024-57768 | CRITICAL | 9.8 | 0.5% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo... |
| CVE-2024-50633 | HIGH | 7.5 | 0.6% | Jan 16, 2025 | A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by... |
| CVE-2024-41746 | MEDIUM | 6.1 | 0.2% | Jan 16, 2025 | IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo... |
| CVE-2024-37181 | LOW | 2.6 | 0.1% | Jan 16, 2025 | Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an au... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now