2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23793MEDIUM6.3The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits au...
CVE-2024-22326MEDIUM6.3IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remo...
CVE-2024-1881CRITICAL9.8AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements us...
CVE-2024-1880HIGH7.8An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/auto...
CVE-2024-1873CRITICAL9.1parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database`...
CVE-2024-0520HIGH8.8A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of specia...
CVE-2024-5509HIGH7.8Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability...
CVE-2024-5508HIGH7.8Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-5507HIGH7.8Luxion KeyShot Viewer KSP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili...
CVE-2024-5506HIGH7.8Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-5505HIGH8.8NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vu...
CVE-2024-5482CRITICAL9.8A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui app...
CVE-2024-5452CRITICAL9.8A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to im...
CVE-2024-5303HIGH7.8Kofax Power PDF PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-5302HIGH7.8Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-5301HIGH7.8Kofax Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-5277HIGH7.5In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password to...
CVE-2024-5269HIGH8.8Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows networ...
CVE-2024-5268MEDIUM6.5Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows n...
CVE-2024-5267HIGH8.8Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows n...
CVE-2024-5256MEDIUM4.3Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows ne...
CVE-2024-5127MEDIUM5.4In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free pla...
CVE-2024-4941HIGH7.5A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability a...
CVE-2024-4889HIGH7.2A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated ...
CVE-2024-4325HIGH8.6A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now