2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6678HIGH8.8An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 pr...
CVE-2024-4472MEDIUM5.5An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 pr...
CVE-2024-45383MEDIUM5A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus ...
CVE-2024-45303MEDIUM6.1Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rende...
CVE-2024-45182MEDIUM5.5An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds che...
CVE-2024-45181HIGH7.8An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds ch...
CVE-2024-36066LOW3.1The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the securit...
CVE-2024-34336MEDIUM5.3User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists i...
CVE-2024-34335MEDIUM6.1ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability ...
CVE-2024-34334HIGH7.5ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password functi...
CVE-2024-25270MEDIUM4.3An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulner...
CVE-2024-8696CRITICAL9.8A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a mal...
CVE-2024-8695CRITICAL9.8A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious e...
CVE-2024-41629MEDIUM5.5An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive informa...
CVE-2024-8754HIGH8.1An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, a...
CVE-2024-8640HIGH8.8An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to...
CVE-2024-8635MEDIUM6.5A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to ...
CVE-2024-8631HIGH7.2A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7,...
CVE-2024-8124HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 pr...
CVE-2024-6840MEDIUM6.6An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S A...
CVE-2024-6446LOW3.5An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17....
CVE-2024-6389MEDIUM4.3An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and...
CVE-2024-5435MEDIUM6.5An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all ve...
CVE-2024-4660HIGH7.5An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting...
CVE-2024-4612MEDIUM6.1An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now