2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3099 | MEDIUM | 5.4 | 0.4% | Jun 6, 2024 | A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploit... |
| CVE-2024-3095 | HIGH | 7.7 | 0.7% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langch... |
| CVE-2024-37364 | MEDIUM | 6.8 | 0.3% | Jun 6, 2024 | Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attac... |
| CVE-2024-37154 | MEDIUM | 5.3 | 0.4% | Jun 6, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not y... |
| CVE-2024-37153 | HIGH | 7.5 | 0.6% | Jun 6, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using ... |
| CVE-2024-36740 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative num... |
| CVE-2024-36735 | MEDIUM | 5.3 | 0.4% | Jun 6, 2024 | OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating. |
| CVE-2024-36734 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti... |
| CVE-2024-36732 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is proce... |
| CVE-2024-36730 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti... |
| CVE-2024-32873 | MEDIUM | 4.3 | 0.4% | Jun 6, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly whe... |
| CVE-2024-30373 | HIGH | 7.8 | 0.6% | Jun 6, 2024 | Kofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2024-2965 | MEDIUM | 4.7 | 0.3% | Jun 6, 2024 | A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, ... |
| CVE-2024-2928 | HIGH | 7.5 | 21.8% | Jun 6, 2024 | A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix... |
| CVE-2024-2624 | CRITICAL | 9.8 | 1.3% | Jun 6, 2024 | A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically w... |
| CVE-2024-2548 | HIGH | 7.5 | 0.9% | Jun 6, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lol... |
| CVE-2024-2383 | MEDIUM | 6.1 | 0.4% | Jun 6, 2024 | A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failu... |
| CVE-2024-2362 | CRITICAL | 9.1 | 1.1% | Jun 6, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper ... |
| CVE-2024-2360 | CRITICAL | 9.8 | 1.9% | Jun 6, 2024 | parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient... |
| CVE-2024-2359 | CRITICAL | 9.8 | 1.2% | Jun 6, 2024 | A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and exe... |
| CVE-2024-2288 | HIGH | 8.3 | 0.3% | Jun 6, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms appli... |
| CVE-2024-2213 | LOW | 3.3 | 0.2% | Jun 6, 2024 | An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms... |
| CVE-2024-2171 | MEDIUM | 4.8 | 0.4% | Jun 6, 2024 | A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within t... |
| CVE-2024-2035 | MEDIUM | 6.5 | 0.6% | Jun 6, 2024 | An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1... |
| CVE-2024-2032 | LOW | 3.1 | 0.3% | Jun 6, 2024 | A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creati... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now