2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32034MEDIUM4.8decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza...
CVE-2024-8661MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r...
CVE-2024-36261MEDIUM5.7Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall...
CVE-2024-36247MEDIUM5.7Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ...
CVE-2024-34545MEDIUM5.7Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot...
CVE-2024-33848MEDIUM5.5Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena...
CVE-2024-32940MEDIUM5.7Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent...
CVE-2024-32666MEDIUM5.5NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to poten...
CVE-2024-28170MEDIUM5.5Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ...
CVE-2024-24968MEDIUM5.6Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to pote...
CVE-2024-23984MEDIUM6.8Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable ...
CVE-2024-45835MEDIUM6.5Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather...
CVE-2024-39772MEDIUM5.3Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen...
CVE-2024-38315MEDIUM6.5IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent...
CVE-2024-46970MEDIUM6.1In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
CVE-2024-45833MEDIUM6.5Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible...
CVE-2024-1578MEDIUM5.3The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fa...
CVE-2024-8780MEDIUM6.5OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote...
CVE-2024-8778MEDIUM6.5OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attack...
CVE-2024-8776MEDIUM6.1SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers t...
CVE-2024-46942MEDIUM6.5In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can co...
CVE-2024-46918MEDIUM4.9app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensiti...
CVE-2024-44059MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Cus...
CVE-2024-44058MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat...
CVE-2024-44057MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now