2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23344MEDIUM6.5Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get ac...
CVE-2024-1251CRITICAL9.8A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of ...
CVE-2024-24594MEDIUM5.4A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform ...
CVE-2024-24593HIGH8.8A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI...
CVE-2024-24592CRITICAL9.8Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta...
CVE-2024-24591HIGH8.8A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a ...
CVE-2024-24590HIGH8.8Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platf...
CVE-2024-0911MEDIUM5.5A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into proce...
CVE-2024-0690MEDIUM5.5An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in...
CVE-2024-24943MEDIUM5.5In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
CVE-2024-24942MEDIUM5.3In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
CVE-2024-24941MEDIUM5.3In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an i...
CVE-2024-24940MEDIUM4.3In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
CVE-2024-24939MEDIUM5.3In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
CVE-2024-24938MEDIUM5.3In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
CVE-2024-24937MEDIUM5.4In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
CVE-2024-24936MEDIUM5.3In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
CVE-2024-23917CRITICAL9.8In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
CVE-2024-23673HIGH7.5Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affe...
CVE-2024-25140CRITICAL9.8A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Au...
CVE-2024-0684MEDIUM5.5A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred byt...
CVE-2024-22365MEDIUM5.5linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo ...
CVE-2024-22433CRITICAL9.8 Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSetti...
CVE-2024-23304HIGH7.5Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) co...
CVE-2024-24808MEDIUM6.1pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorre...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now