2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29068 | MEDIUM | 6.6 | 0.2% | Jul 25, 2024 | In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is... |
| CVE-2024-28772 | MEDIUM | 5.4 | 0.3% | Jul 25, 2024 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cros... |
| CVE-2024-41801 | MEDIUM | 6.1 | 0.3% | Jul 25, 2024 | OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the defau... |
| CVE-2024-41806 | MEDIUM | 5.3 | 0.3% | Jul 25, 2024 | The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information... |
| CVE-2024-36111 | MEDIUM | 6.3 | 8.4% | Jul 25, 2024 | KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token v... |
| CVE-2024-39674 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect ... |
| CVE-2024-39671 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2024-39670 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulner... |
| CVE-2024-41707 | MEDIUM | 5.4 | 0.3% | Jul 25, 2024 | An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A r... |
| CVE-2024-41706 | MEDIUM | 5.4 | 0.3% | Jul 25, 2024 | A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer u... |
| CVE-2024-41705 | MEDIUM | 5.4 | 0.3% | Jul 25, 2024 | A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user co... |
| CVE-2024-6972 | MEDIUM | 6.5 | 0.2% | Jul 25, 2024 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed ... |
| CVE-2024-7057 | MEDIUM | 4.3 | 0.4% | Jul 25, 2024 | An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, start... |
| CVE-2024-7047 | MEDIUM | 5.4 | 0.3% | Jul 25, 2024 | A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior... |
| CVE-2024-7091 | MEDIUM | 5 | 0.3% | Jul 24, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 pr... |
| CVE-2024-7060 | MEDIUM | 6.5 | 0.3% | Jul 24, 2024 | An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior ... |
| CVE-2024-5067 | MEDIUM | 4.9 | 0.5% | Jul 24, 2024 | An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prio... |
| CVE-2024-40137 | MEDIUM | 5.5 | 0.7% | Jul 24, 2024 | Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Comp... |
| CVE-2024-41666 | MEDIUM | 6.5 | 0.7% | Jul 24, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows u... |
| CVE-2024-37533 | MEDIUM | 4.6 | 0.2% | Jul 24, 2024 | IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to... |
| CVE-2024-21684 | MEDIUM | 4.3 | 0.2% | Jul 24, 2024 | There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbu... |
| CVE-2024-7079 | MEDIUM | 6.5 | 0.4% | Jul 24, 2024 | A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation ... |
| CVE-2024-40575 | MEDIUM | 5.5 | 0.1% | Jul 24, 2024 | An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of s... |
| CVE-2024-22444 | MEDIUM | 6.1 | 0.3% | Jul 24, 2024 | A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attack... |
| CVE-2024-7068 | MEDIUM | 4.6 | 0.4% | Jul 24, 2024 | A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now