2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41135HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot...
CVE-2024-41134HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot...
CVE-2024-41133HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot...
CVE-2024-36535CRITICAL9.8Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining t...
CVE-2024-36534HIGH8.4Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin...
CVE-2024-36533CRITICAL9.8Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining th...
CVE-2024-33519HIGH7.2A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an ...
CVE-2024-40495HIGH8A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute a...
CVE-2024-40137MEDIUM5.5Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Comp...
CVE-2024-36538HIGH8.8Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining...
CVE-2024-36537HIGH7.2Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain...
CVE-2024-36536CRITICAL9.8Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining th...
CVE-2024-41672HIGH7.5DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading...
CVE-2024-41667HIGH8.8OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in Re...
CVE-2024-41666MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows u...
CVE-2024-37533MEDIUM4.6IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to...
CVE-2024-21684MEDIUM4.3There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbu...
CVE-2024-41662CRITICAL9.6VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown renderin...
CVE-2024-41110CRITICAL9.9Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detect...
CVE-2024-36540CRITICAL9.8Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by ob...
CVE-2024-36539CRITICAL9.8Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t...
CVE-2024-7079MEDIUM6.5A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation ...
CVE-2024-7069HIGH7.5A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi...
CVE-2024-40575MEDIUM5.5An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of s...
CVE-2024-40422CRITICAL9.1The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now