2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45800MEDIUM5Snappymail is an open source web-based email client. SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS ...
CVE-2024-42796MEDIUM5.9An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management...
CVE-2024-42795MEDIUM4.2An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_use...
CVE-2024-42794MEDIUM4.7Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
CVE-2024-34016MEDIUM6.5Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2024-22013MEDIUM5.3U-Boot environment is read from unauthenticated partition.
CVE-2024-45801MEDIUM6.1DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that m...
CVE-2024-45799MEDIUM6.1FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/b...
CVE-2024-39910MEDIUM4.8decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza...
CVE-2024-32034MEDIUM4.8decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza...
CVE-2024-8661MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r...
CVE-2024-36261MEDIUM5.7Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall...
CVE-2024-36247MEDIUM5.7Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ...
CVE-2024-34545MEDIUM5.7Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot...
CVE-2024-33848MEDIUM5.5Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena...
CVE-2024-32940MEDIUM5.7Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent...
CVE-2024-32666MEDIUM5.5NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to poten...
CVE-2024-28170MEDIUM5.5Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ...
CVE-2024-24968MEDIUM5.6Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to pote...
CVE-2024-23984MEDIUM6.8Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable ...
CVE-2024-45835MEDIUM6.5Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather...
CVE-2024-39772MEDIUM5.3Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen...
CVE-2024-38315MEDIUM6.5IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent...
CVE-2024-46970MEDIUM6.1In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
CVE-2024-45833MEDIUM6.5Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now