2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41135 | HIGH | 7.2 | 0.8% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-41134 | HIGH | 7.2 | 0.7% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-41133 | HIGH | 7.2 | 0.8% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-36535 | CRITICAL | 9.8 | 0.5% | Jul 24, 2024 | Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining t... |
| CVE-2024-36534 | HIGH | 8.4 | 0.2% | Jul 24, 2024 | Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin... |
| CVE-2024-36533 | CRITICAL | 9.8 | 0.5% | Jul 24, 2024 | Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining th... |
| CVE-2024-33519 | HIGH | 7.2 | 0.7% | Jul 24, 2024 | A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an ... |
| CVE-2024-40495 | HIGH | 8 | 0.9% | Jul 24, 2024 | A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute a... |
| CVE-2024-40137 | MEDIUM | 5.5 | 0.7% | Jul 24, 2024 | Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Comp... |
| CVE-2024-36538 | HIGH | 8.8 | 0.6% | Jul 24, 2024 | Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining... |
| CVE-2024-36537 | HIGH | 7.2 | 0.4% | Jul 24, 2024 | Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain... |
| CVE-2024-36536 | CRITICAL | 9.8 | 0.5% | Jul 24, 2024 | Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining th... |
| CVE-2024-41672 | HIGH | 7.5 | 0.8% | Jul 24, 2024 | DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading... |
| CVE-2024-41667 | HIGH | 8.8 | 3.5% | Jul 24, 2024 | OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in Re... |
| CVE-2024-41666 | MEDIUM | 6.5 | 0.7% | Jul 24, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows u... |
| CVE-2024-37533 | MEDIUM | 4.6 | 0.2% | Jul 24, 2024 | IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to... |
| CVE-2024-21684 | MEDIUM | 4.3 | 0.2% | Jul 24, 2024 | There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbu... |
| CVE-2024-41662 | CRITICAL | 9.6 | 1.6% | Jul 24, 2024 | VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown renderin... |
| CVE-2024-41110 | CRITICAL | 9.9 | 16.5% | Jul 24, 2024 | Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detect... |
| CVE-2024-36540 | CRITICAL | 9.8 | 0.4% | Jul 24, 2024 | Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by ob... |
| CVE-2024-36539 | CRITICAL | 9.8 | 1.3% | Jul 24, 2024 | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t... |
| CVE-2024-7079 | MEDIUM | 6.5 | 0.4% | Jul 24, 2024 | A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation ... |
| CVE-2024-7069 | HIGH | 7.5 | 0.4% | Jul 24, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi... |
| CVE-2024-40575 | MEDIUM | 5.5 | 0.1% | Jul 24, 2024 | An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of s... |
| CVE-2024-40422 | CRITICAL | 9.1 | 11.4% | Jul 24, 2024 | The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now