2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52513MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share li...
CVE-2024-52512MEDIUM6.1user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that w...
CVE-2024-52511MEDIUM6.5Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or v...
CVE-2024-52510HIGH7.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client...
CVE-2024-52509MEDIUM5.7Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly al...
CVE-2024-52508HIGH8.1Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mai...
CVE-2024-52507MEDIUM4.3Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is s...
CVE-2024-50800MEDIUM5.4Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary...
CVE-2024-47759MEDIUM4.8GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. T...
CVE-2024-46467HIGH7.8By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f...
CVE-2024-46466HIGH7.8By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)...
CVE-2024-46465HIGH7.8By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file...
CVE-2024-46463HIGH7.8By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file...
CVE-2024-46462HIGH7.8By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil...
CVE-2024-46383LOW2.4Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected ...
CVE-2024-41678MEDIUM6.1GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ...
CVE-2024-40638HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulner...
CVE-2024-24450MEDIUM5.3Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN...
CVE-2024-24449MEDIUM6.5An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows at...
CVE-2024-24447MEDIUM5.3A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allow...
CVE-2024-11251HIGH8.8A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some un...
CVE-2024-11250CRITICAL9.8A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulner...
CVE-2024-52528CRITICAL9.3Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for...
CVE-2024-52525HIGH7.5Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen...
CVE-2024-52523MEDIUM6.5Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external stora...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now