2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-29068MEDIUM6.6In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is...
CVE-2024-28772MEDIUM5.4IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cros...
CVE-2024-41801MEDIUM6.1OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the defau...
CVE-2024-41806MEDIUM5.3The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information...
CVE-2024-36111MEDIUM6.3KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token v...
CVE-2024-39674MEDIUM5.5Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect ...
CVE-2024-39671MEDIUM5.5Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability ...
CVE-2024-39670MEDIUM5.5Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulner...
CVE-2024-41707MEDIUM5.4An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A r...
CVE-2024-41706MEDIUM5.4A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer u...
CVE-2024-41705MEDIUM5.4A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user co...
CVE-2024-6972MEDIUM6.5In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed ...
CVE-2024-7057MEDIUM4.3An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, start...
CVE-2024-7047MEDIUM5.4A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior...
CVE-2024-7091MEDIUM5An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 pr...
CVE-2024-7060MEDIUM6.5An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior ...
CVE-2024-5067MEDIUM4.9An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prio...
CVE-2024-40137MEDIUM5.5Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Comp...
CVE-2024-41666MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows u...
CVE-2024-37533MEDIUM4.6IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to...
CVE-2024-21684MEDIUM4.3There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbu...
CVE-2024-7079MEDIUM6.5A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation ...
CVE-2024-40575MEDIUM5.5An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of s...
CVE-2024-22444MEDIUM6.1A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attack...
CVE-2024-7068MEDIUM4.6A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now