2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38360MEDIUM4.9Discourse is an open source platform for community discussion. In affected versions by creating replacement words with a...
CVE-2024-40631HIGH8.1Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlPars...
CVE-2024-37386MEDIUM4.2An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Cert...
CVE-2024-36438HIGH7.3eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check...
CVE-2024-36434HIGH7.5An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmw...
CVE-2024-36433HIGH7.5An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with...
CVE-2024-36432HIGH7.5An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN mo...
CVE-2024-31946MEDIUM4.2An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through ...
CVE-2024-40416CRITICAL9.8A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack...
CVE-2024-40415CRITICAL9.8A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-b...
CVE-2024-39827MEDIUM5.5Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an...
CVE-2024-39826MEDIUM6.8Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct...
CVE-2024-39821MEDIUM4.4Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authentic...
CVE-2024-39820MEDIUM5Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may all...
CVE-2024-39819HIGH7.3Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to co...
CVE-2024-37016MEDIUM6.8Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.
CVE-2024-27241HIGH7.5Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via ...
CVE-2024-27240HIGH7.8Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a p...
CVE-2024-27238MEDIUM6.3Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated ...
CVE-2024-40414CRITICAL9.8A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-b...
CVE-2024-40560HIGH7.3Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.
CVE-2024-40555MEDIUM5.3Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.
CVE-2024-40554HIGH7.5An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.
CVE-2024-40553MEDIUM4.9Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
CVE-2024-6716Rejected reason: Invalid security issue.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now