2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32034 | MEDIUM | 4.8 | 0.4% | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza... |
| CVE-2024-8661 | MEDIUM | 4.8 | 0.4% | Sep 16, 2024 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r... |
| CVE-2024-36261 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall... |
| CVE-2024-36247 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ... |
| CVE-2024-34545 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot... |
| CVE-2024-33848 | MEDIUM | 5.5 | 0.1% | Sep 16, 2024 | Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena... |
| CVE-2024-32940 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent... |
| CVE-2024-32666 | MEDIUM | 5.5 | 0.1% | Sep 16, 2024 | NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to poten... |
| CVE-2024-28170 | MEDIUM | 5.5 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ... |
| CVE-2024-24968 | MEDIUM | 5.6 | 0.2% | Sep 16, 2024 | Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to pote... |
| CVE-2024-23984 | MEDIUM | 6.8 | 0.2% | Sep 16, 2024 | Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable ... |
| CVE-2024-45835 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather... |
| CVE-2024-39772 | MEDIUM | 5.3 | 0.3% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen... |
| CVE-2024-38315 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent... |
| CVE-2024-46970 | MEDIUM | 6.1 | 0.4% | Sep 16, 2024 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible |
| CVE-2024-45833 | MEDIUM | 6.5 | 0.3% | Sep 16, 2024 | Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible... |
| CVE-2024-1578 | MEDIUM | 5.3 | 0.2% | Sep 16, 2024 | The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fa... |
| CVE-2024-8780 | MEDIUM | 6.5 | 0.4% | Sep 16, 2024 | OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote... |
| CVE-2024-8778 | MEDIUM | 6.5 | 0.6% | Sep 16, 2024 | OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attack... |
| CVE-2024-8776 | MEDIUM | 6.1 | 0.3% | Sep 16, 2024 | SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers t... |
| CVE-2024-46942 | MEDIUM | 6.5 | 0.4% | Sep 15, 2024 | In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can co... |
| CVE-2024-46918 | MEDIUM | 4.9 | 0.4% | Sep 15, 2024 | app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensiti... |
| CVE-2024-44059 | MEDIUM | 5.4 | 0.2% | Sep 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Cus... |
| CVE-2024-44058 | MEDIUM | 5.4 | 0.3% | Sep 15, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat... |
| CVE-2024-44057 | MEDIUM | 5.4 | 0.3% | Sep 15, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now