Vulnerabilities (CVE)

Total 396088 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38505 1 Jetbrains 1 Youtrack 2026-06-17 N/A 5.3 MEDIUM
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
CVE-2024-38504 1 Jetbrains 1 Youtrack 2026-06-17 N/A 4.3 MEDIUM
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
CVE-2024-38503 1 Apache 1 Syncope 2026-06-17 N/A 5.4 MEDIUM
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
CVE-2024-38502 1 Pepperl-fuchs 48 Eip\/modbus Firmware, Ethernet\/ip Firmware, Icdm-rx\/en-2db9\/rj45-din and 45 more 2026-06-17 N/A 7.1 HIGH
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
CVE-2024-38501 1 Pepperl-fuchs 48 Eip\/modbus Firmware, Ethernet\/ip Firmware, Icdm-rx\/en-2db9\/rj45-din and 45 more 2026-06-17 N/A 6.1 MEDIUM
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
CVE-2024-38499 2026-06-17 N/A 8.8 HIGH
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.
CVE-2024-38496 2026-06-17 N/A N/A
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
CVE-2024-38495 2026-06-17 N/A N/A
A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
CVE-2024-38494 2026-06-17 N/A N/A
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
CVE-2024-38493 1 Broadcom 1 Symantec Privileged Access Management 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
CVE-2024-38492 2026-06-17 N/A N/A
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
CVE-2024-38491 2026-06-17 N/A N/A
The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
CVE-2024-38490 1 Dell 1 Emc Idrac Service Module 2026-06-17 N/A 5.8 MEDIUM
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
CVE-2024-38489 1 Dell 1 Emc Idrac Service Module 2026-06-17 N/A 3.1 LOW
Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.
CVE-2024-38488 1 Dell 1 Recoverpoint For Virtual Machines 2026-06-17 N/A 6.5 MEDIUM
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise. This allows attackers to brute-force the password of valid users in an automated manner.
CVE-2024-38487 2026-06-17 N/A 7.0 HIGH
api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.
CVE-2024-38486 1 Dell 1 Smartfabric Os10 2026-06-17 N/A 7.5 HIGH
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
CVE-2024-38485 1 Dell 1 Elastic Cloud Storage 2026-06-17 N/A 4.3 MEDIUM
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
CVE-2024-38483 1 Dell 82 Embedded Box Pc 5000, Embedded Box Pc 5000 Firmware, Latitude 12 Rugged Extreme 7214 and 79 more 2026-06-17 N/A 5.8 MEDIUM
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CVE-2024-38482 1 Dell 1 Cloudlink 2026-06-17 N/A 6.6 MEDIUM
CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and retrieve sensitive information from the database.