2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39776HIGH7.5Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
CVE-2024-8088HIGH8.7There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the mo...
CVE-2024-39717HIGH7.2The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only avai...
CVE-2024-7634MEDIUM4.9NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwri...
CVE-2024-42773CRITICAL9.1An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management Sys...
CVE-2024-42767HIGH7.2Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
CVE-2024-42776HIGH7.2Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
CVE-2024-42775CRITICAL9.1An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management Syst...
CVE-2024-42774HIGH7.5An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0,...
CVE-2024-42772HIGH7.5An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which...
CVE-2024-42768MEDIUM6.8A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_...
CVE-2024-8041MEDIUM6.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior t...
CVE-2024-7110MEDIUM6.4An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prio...
CVE-2024-6502MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prio...
CVE-2024-45193MEDIUM4.3An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validati...
CVE-2024-45192MEDIUM5.3An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decodi...
CVE-2024-45191MEDIUM5.3An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks du...
CVE-2024-43780MEDIUM4.3Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a gu...
CVE-2024-42771MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel...
CVE-2024-42770MEDIUM4.7A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management Sys...
CVE-2024-42769MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management...
CVE-2024-42497MEDIUM4.9Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permission...
CVE-2024-42490HIGH7.5authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica...
CVE-2024-40884LOW2.7Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user...
CVE-2024-3127MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now