2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45801MEDIUM6.1DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that m...
CVE-2024-45799MEDIUM6.1FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/b...
CVE-2024-39910MEDIUM4.8decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza...
CVE-2024-32034MEDIUM4.8decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza...
CVE-2024-8661MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r...
CVE-2024-36261MEDIUM5.7Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall...
CVE-2024-36247MEDIUM5.7Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ...
CVE-2024-34545MEDIUM5.7Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot...
CVE-2024-34543HIGH7.8Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent...
CVE-2024-34153HIGH7.8Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user ...
CVE-2024-33848MEDIUM5.5Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena...
CVE-2024-32940MEDIUM5.7Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent...
CVE-2024-32666MEDIUM5.5NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to poten...
CVE-2024-28170MEDIUM5.5Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ...
CVE-2024-24968MEDIUM5.6Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to pote...
CVE-2024-23984MEDIUM6.8Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable ...
CVE-2024-23599HIGH8.3Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potenti...
CVE-2024-21871HIGH7.5Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl...
CVE-2024-21829HIGH8.7Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to pot...
CVE-2024-21781HIGH7.2Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable informatio...
CVE-2024-8752HIGH7.5The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to r...
CVE-2024-44623CRITICAL9.8An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.j...
CVE-2024-7104CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injecti...
CVE-2024-7098CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. ...
CVE-2024-6401CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Ins...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now