2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7110MEDIUM6.4An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prio...
CVE-2024-6502MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prio...
CVE-2024-45193MEDIUM4.3An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validati...
CVE-2024-45192MEDIUM5.3An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decodi...
CVE-2024-45191MEDIUM5.3An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks du...
CVE-2024-43780MEDIUM4.3Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a gu...
CVE-2024-42771MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel...
CVE-2024-42770MEDIUM4.7A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management Sys...
CVE-2024-42769MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management...
CVE-2024-42497MEDIUM4.9Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permission...
CVE-2024-3127MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting...
CVE-2024-36441MEDIUM5.4Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to ope...
CVE-2024-43787MEDIUM5Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypass...
CVE-2024-43398MEDIUM5.9REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many...
CVE-2024-36440MEDIUM6.8An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may ...
CVE-2024-7848MEDIUM6.5The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Refe...
CVE-2024-39746MEDIUM5.9IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive inform...
CVE-2024-39744MEDIUM4.3IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could ...
CVE-2024-35151MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a...
CVE-2024-7778MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2024-6870MEDIUM5.4The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in ...
CVE-2024-8072MEDIUM5.3Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
CVE-2024-43813MEDIUM4.3Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticat...
CVE-2024-42411MEDIUM5.3Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST ...
CVE-2024-39836MEDIUM6.5Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synt...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now