2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52602MEDIUM5.3Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) i...
CVE-2024-36403HIGH7.5Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ...
CVE-2024-36402MEDIUM5.3Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ...
CVE-2024-57684CRITICAL9.8An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at...
CVE-2024-57683MEDIUM4.3An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenti...
CVE-2024-57682MEDIUM6.5An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows u...
CVE-2024-57681MEDIUM5.3An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a...
CVE-2024-57680MEDIUM5.3An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth...
CVE-2024-57679MEDIUM6.5An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthe...
CVE-2024-57678MEDIUM6.5An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated ...
CVE-2024-57677MEDIUM6.5An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a...
CVE-2024-57676MEDIUM6.5An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth...
CVE-2024-52594MEDIUM4.3Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery,...
CVE-2024-57776MEDIUM4.6A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allow...
CVE-2024-57775HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?ins...
CVE-2024-57774MEDIUM4.8A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01....
CVE-2024-57773MEDIUM4.8A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ...
CVE-2024-57772MEDIUM4.8A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ...
CVE-2024-57771MEDIUM4.8A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow...
CVE-2024-57770HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr...
CVE-2024-57769HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa...
CVE-2024-57768CRITICAL9.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo...
CVE-2024-50633HIGH7.5A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by...
CVE-2024-41746MEDIUM6.1IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo...
CVE-2024-37181LOW2.6Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an au...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now