2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36441MEDIUM5.4Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to ope...
CVE-2024-43787MEDIUM5Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypass...
CVE-2024-43785LOW2.5gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying ...
CVE-2024-43398MEDIUM5.9REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many...
CVE-2024-36445CRITICAL9.8Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.
CVE-2024-36444HIGH8.1cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device...
CVE-2024-36442HIGH8.8cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar...
CVE-2024-36440MEDIUM6.8An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may ...
CVE-2024-36439CRITICAL9.4Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the dev...
CVE-2024-36443HIGH7.6Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonym...
CVE-2024-43331CRITICAL9.8Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
CVE-2024-7848MEDIUM6.5The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Refe...
CVE-2024-39746MEDIUM5.9IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive inform...
CVE-2024-39745HIGH7.5IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that ...
CVE-2024-39744MEDIUM4.3IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could ...
CVE-2024-35151MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a...
CVE-2024-7778MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2024-6870MEDIUM5.4The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in ...
CVE-2024-8072MEDIUM5.3Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
CVE-2024-8071HIGH7.2Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can...
CVE-2024-43813MEDIUM4.3Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticat...
CVE-2024-42411MEDIUM5.3Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST ...
CVE-2024-40886HIGH8.8Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the...
CVE-2024-39836MEDIUM6.5Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synt...
CVE-2024-39810MEDIUM4.9Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the Elasti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now