2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23344 | MEDIUM | 6.5 | 0.5% | Feb 6, 2024 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get ac... |
| CVE-2024-1251 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of ... |
| CVE-2024-24594 | MEDIUM | 5.4 | 0.6% | Feb 6, 2024 | A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform ... |
| CVE-2024-24593 | HIGH | 8.8 | 0.4% | Feb 6, 2024 | A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI... |
| CVE-2024-24592 | CRITICAL | 9.8 | 1.0% | Feb 6, 2024 | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta... |
| CVE-2024-24591 | HIGH | 8.8 | 0.8% | Feb 6, 2024 | A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a ... |
| CVE-2024-24590 | HIGH | 8.8 | 2.5% | Feb 6, 2024 | Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platf... |
| CVE-2024-0911 | MEDIUM | 5.5 | 0.3% | Feb 6, 2024 | A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into proce... |
| CVE-2024-0690 | MEDIUM | 5.5 | 0.3% | Feb 6, 2024 | An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in... |
| CVE-2024-24943 | MEDIUM | 5.5 | 0.4% | Feb 6, 2024 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image |
| CVE-2024-24942 | MEDIUM | 5.3 | 32.0% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives |
| CVE-2024-24941 | MEDIUM | 5.3 | 0.3% | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an i... |
| CVE-2024-24940 | MEDIUM | 4.3 | 0.3% | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives |
| CVE-2024-24939 | MEDIUM | 5.3 | 0.3% | Feb 6, 2024 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible |
| CVE-2024-24938 | MEDIUM | 5.3 | 0.7% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation |
| CVE-2024-24937 | MEDIUM | 5.4 | 0.4% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible |
| CVE-2024-24936 | MEDIUM | 5.3 | 0.3% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed |
| CVE-2024-23917 | CRITICAL | 9.8 | 53.7% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible |
| CVE-2024-23673 | HIGH | 7.5 | 1.3% | Feb 6, 2024 | Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affe... |
| CVE-2024-25140 | CRITICAL | 9.8 | 0.5% | Feb 6, 2024 | A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Au... |
| CVE-2024-0684 | MEDIUM | 5.5 | 0.5% | Feb 6, 2024 | A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred byt... |
| CVE-2024-22365 | MEDIUM | 5.5 | 0.5% | Feb 6, 2024 | linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo ... |
| CVE-2024-22433 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSetti... |
| CVE-2024-23304 | HIGH | 7.5 | 0.8% | Feb 6, 2024 | Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) co... |
| CVE-2024-24808 | MEDIUM | 6.1 | 0.5% | Feb 6, 2024 | pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorre... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now