2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45800 | MEDIUM | 5 | 0.3% | Sep 16, 2024 | Snappymail is an open source web-based email client. SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS ... |
| CVE-2024-42796 | MEDIUM | 5.9 | 0.2% | Sep 16, 2024 | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management... |
| CVE-2024-42795 | MEDIUM | 4.2 | 0.2% | Sep 16, 2024 | An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_use... |
| CVE-2024-42794 | MEDIUM | 4.7 | 0.3% | Sep 16, 2024 | Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user. |
| CVE-2024-34016 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-22013 | MEDIUM | 5.3 | 0.2% | Sep 16, 2024 | U-Boot environment is read from unauthenticated partition. |
| CVE-2024-45801 | MEDIUM | 6.1 | 0.8% | Sep 16, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that m... |
| CVE-2024-45799 | MEDIUM | 6.1 | 0.3% | Sep 16, 2024 | FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/b... |
| CVE-2024-39910 | MEDIUM | 4.8 | 0.3% | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza... |
| CVE-2024-32034 | MEDIUM | 4.8 | 0.4% | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza... |
| CVE-2024-8661 | MEDIUM | 4.8 | 0.4% | Sep 16, 2024 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r... |
| CVE-2024-36261 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall... |
| CVE-2024-36247 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ... |
| CVE-2024-34545 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot... |
| CVE-2024-33848 | MEDIUM | 5.5 | 0.1% | Sep 16, 2024 | Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena... |
| CVE-2024-32940 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent... |
| CVE-2024-32666 | MEDIUM | 5.5 | 0.1% | Sep 16, 2024 | NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to poten... |
| CVE-2024-28170 | MEDIUM | 5.5 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ... |
| CVE-2024-24968 | MEDIUM | 5.6 | 0.2% | Sep 16, 2024 | Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to pote... |
| CVE-2024-23984 | MEDIUM | 6.8 | 0.2% | Sep 16, 2024 | Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable ... |
| CVE-2024-45835 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather... |
| CVE-2024-39772 | MEDIUM | 5.3 | 0.3% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen... |
| CVE-2024-38315 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent... |
| CVE-2024-46970 | MEDIUM | 6.1 | 0.4% | Sep 16, 2024 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible |
| CVE-2024-45833 | MEDIUM | 6.5 | 0.3% | Sep 16, 2024 | Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now