2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45835 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather... |
| CVE-2024-39772 | MEDIUM | 5.3 | 0.3% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen... |
| CVE-2024-38315 | MEDIUM | 6.5 | 0.2% | Sep 16, 2024 | IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent... |
| CVE-2024-46419 | CRITICAL | 9.8 | 0.7% | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5... |
| CVE-2024-46937 | HIGH | 7.5 | 0.5% | Sep 16, 2024 | An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Sec... |
| CVE-2024-46451 | CRITICAL | 9.8 | 1.2% | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de... |
| CVE-2024-46424 | HIGH | 7.5 | 0.6% | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which ... |
| CVE-2024-22399 | CRITICAL | 9.8 | 3.3% | Sep 16, 2024 | Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-S... |
| CVE-2024-46970 | MEDIUM | 6.1 | 0.4% | Sep 16, 2024 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible |
| CVE-2024-45833 | MEDIUM | 6.5 | 0.3% | Sep 16, 2024 | Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible... |
| CVE-2024-45698 | CRITICAL | 9.8 | 1.1% | Sep 16, 2024 | Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenti... |
| CVE-2024-45697 | CRITICAL | 9.8 | 1.0% | Sep 16, 2024 | Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN p... |
| CVE-2024-45696 | HIGH | 8.8 | 0.6% | Sep 16, 2024 | Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, ... |
| CVE-2024-45695 | CRITICAL | 9.8 | 1.6% | Sep 16, 2024 | The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which... |
| CVE-2024-45694 | CRITICAL | 9.8 | 1.9% | Sep 16, 2024 | The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which... |
| CVE-2024-39613 | HIGH | 7.8 | 0.3% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows ... |
| CVE-2024-1578 | MEDIUM | 5.3 | 0.2% | Sep 16, 2024 | The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fa... |
| CVE-2024-8780 | MEDIUM | 6.5 | 0.4% | Sep 16, 2024 | OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote... |
| CVE-2024-8779 | HIGH | 8.8 | 0.5% | Sep 16, 2024 | OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowi... |
| CVE-2024-8778 | MEDIUM | 6.5 | 0.6% | Sep 16, 2024 | OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attack... |
| CVE-2024-8777 | HIGH | 7.5 | 0.5% | Sep 16, 2024 | OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read ar... |
| CVE-2024-8776 | MEDIUM | 6.1 | 0.3% | Sep 16, 2024 | SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers t... |
| CVE-2024-46958 | CRITICAL | 9.1 | 0.6% | Sep 16, 2024 | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may becom... |
| CVE-2024-8880 | CRITICAL | 9.8 | 0.7% | Sep 16, 2024 | A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown functio... |
| CVE-2024-46943 | HIGH | 7.5 | 0.6% | Sep 15, 2024 | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue contr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now