2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41808MEDIUM5.4The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uplo...
CVE-2024-40324MEDIUM5.4A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) charac...
CVE-2024-38289CRITICAL9.8A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all...
CVE-2024-38288HIGH7.2A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow...
CVE-2024-38287CRITICAL9.8The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticat...
CVE-2024-29069HIGH7.3In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap...
CVE-2024-29068MEDIUM6.6In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is...
CVE-2024-40318HIGH7.2An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploadi...
CVE-2024-1724HIGH8.2In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict w...
CVE-2024-40873LOW3.4There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio...
CVE-2024-28772MEDIUM5.4IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cros...
CVE-2024-7007CRITICAL9.8Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an ...
CVE-2024-41801MEDIUM6.1OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the defau...
CVE-2024-41800HIGH7.5Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity p...
CVE-2024-40872HIGH8.4There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to vers...
CVE-2024-36542HIGH8.8Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the s...
CVE-2024-7101HIGH7.3A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue...
CVE-2024-41806MEDIUM5.3The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information...
CVE-2024-36111MEDIUM6.3KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token v...
CVE-2024-39674MEDIUM5.5Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect ...
CVE-2024-39673HIGH7.1Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vu...
CVE-2024-39672HIGH7.1Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affe...
CVE-2024-39671MEDIUM5.5Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability ...
CVE-2024-39670MEDIUM5.5Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulner...
CVE-2024-6589HIGH8.8The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now