2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45801 | MEDIUM | 6.1 | 0.8% | Sep 16, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that m... |
| CVE-2024-45799 | MEDIUM | 6.1 | 0.3% | Sep 16, 2024 | FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/b... |
| CVE-2024-39910 | MEDIUM | 4.8 | 0.3% | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza... |
| CVE-2024-32034 | MEDIUM | 4.8 | 0.4% | Sep 16, 2024 | decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organiza... |
| CVE-2024-8661 | MEDIUM | 4.8 | 0.4% | Sep 16, 2024 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r... |
| CVE-2024-36261 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall... |
| CVE-2024-36247 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ... |
| CVE-2024-34545 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot... |
| CVE-2024-34543 | HIGH | 7.8 | 0.1% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent... |
| CVE-2024-34153 | HIGH | 7.8 | 0.1% | Sep 16, 2024 | Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user ... |
| CVE-2024-33848 | MEDIUM | 5.5 | 0.1% | Sep 16, 2024 | Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena... |
| CVE-2024-32940 | MEDIUM | 5.7 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent... |
| CVE-2024-32666 | MEDIUM | 5.5 | 0.1% | Sep 16, 2024 | NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to poten... |
| CVE-2024-28170 | MEDIUM | 5.5 | 0.2% | Sep 16, 2024 | Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable ... |
| CVE-2024-24968 | MEDIUM | 5.6 | 0.2% | Sep 16, 2024 | Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to pote... |
| CVE-2024-23984 | MEDIUM | 6.8 | 0.2% | Sep 16, 2024 | Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable ... |
| CVE-2024-23599 | HIGH | 8.3 | 0.1% | Sep 16, 2024 | Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potenti... |
| CVE-2024-21871 | HIGH | 7.5 | 0.2% | Sep 16, 2024 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl... |
| CVE-2024-21829 | HIGH | 8.7 | 0.2% | Sep 16, 2024 | Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to pot... |
| CVE-2024-21781 | HIGH | 7.2 | 0.2% | Sep 16, 2024 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable informatio... |
| CVE-2024-8752 | HIGH | 7.5 | 11.8% | Sep 16, 2024 | The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to r... |
| CVE-2024-44623 | CRITICAL | 9.8 | 1.2% | Sep 16, 2024 | An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.j... |
| CVE-2024-7104 | CRITICAL | 9.8 | 0.5% | Sep 16, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injecti... |
| CVE-2024-7098 | CRITICAL | 9.8 | 0.5% | Sep 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. ... |
| CVE-2024-6401 | CRITICAL | 9.8 | 0.4% | Sep 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Ins... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now