2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45835MEDIUM6.5Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather...
CVE-2024-39772MEDIUM5.3Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen...
CVE-2024-38315MEDIUM6.5IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent...
CVE-2024-46419CRITICAL9.8TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5...
CVE-2024-46937HIGH7.5An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Sec...
CVE-2024-46451CRITICAL9.8TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de...
CVE-2024-46424HIGH7.5TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which ...
CVE-2024-22399CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-S...
CVE-2024-46970MEDIUM6.1In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
CVE-2024-45833MEDIUM6.5Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible...
CVE-2024-45698CRITICAL9.8Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenti...
CVE-2024-45697CRITICAL9.8Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN p...
CVE-2024-45696HIGH8.8Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, ...
CVE-2024-45695CRITICAL9.8The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which...
CVE-2024-45694CRITICAL9.8The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which...
CVE-2024-39613HIGH7.8Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows ...
CVE-2024-1578MEDIUM5.3The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fa...
CVE-2024-8780MEDIUM6.5OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote...
CVE-2024-8779HIGH8.8OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowi...
CVE-2024-8778MEDIUM6.5OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attack...
CVE-2024-8777HIGH7.5OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read ar...
CVE-2024-8776MEDIUM6.1SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers t...
CVE-2024-46958CRITICAL9.1In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may becom...
CVE-2024-8880CRITICAL9.8A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown functio...
CVE-2024-46943HIGH7.5An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue contr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now