2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23793 | MEDIUM | 6.3 | 0.8% | Jun 6, 2024 | The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits au... |
| CVE-2024-22326 | MEDIUM | 6.3 | 0.4% | Jun 6, 2024 | IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remo... |
| CVE-2024-1881 | CRITICAL | 9.8 | 1.4% | Jun 6, 2024 | AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements us... |
| CVE-2024-1880 | HIGH | 7.8 | 1.0% | Jun 6, 2024 | An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/auto... |
| CVE-2024-1873 | CRITICAL | 9.1 | 13.4% | Jun 6, 2024 | parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database`... |
| CVE-2024-0520 | HIGH | 8.8 | 2.4% | Jun 6, 2024 | A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of specia... |
| CVE-2024-5509 | HIGH | 7.8 | 0.5% | Jun 6, 2024 | Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability... |
| CVE-2024-5508 | HIGH | 7.8 | 0.7% | Jun 6, 2024 | Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2024-5507 | HIGH | 7.8 | 0.8% | Jun 6, 2024 | Luxion KeyShot Viewer KSP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili... |
| CVE-2024-5506 | HIGH | 7.8 | 0.7% | Jun 6, 2024 | Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2024-5505 | HIGH | 8.8 | 47.0% | Jun 6, 2024 | NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vu... |
| CVE-2024-5482 | CRITICAL | 9.8 | 0.7% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui app... |
| CVE-2024-5452 | CRITICAL | 9.8 | 26.5% | Jun 6, 2024 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to im... |
| CVE-2024-5303 | HIGH | 7.8 | 0.5% | Jun 6, 2024 | Kofax Power PDF PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2024-5302 | HIGH | 7.8 | 0.5% | Jun 6, 2024 | Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2024-5301 | HIGH | 7.8 | 0.5% | Jun 6, 2024 | Kofax Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2024-5277 | HIGH | 7.5 | 0.4% | Jun 6, 2024 | In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password to... |
| CVE-2024-5269 | HIGH | 8.8 | 1.2% | Jun 6, 2024 | Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows networ... |
| CVE-2024-5268 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows n... |
| CVE-2024-5267 | HIGH | 8.8 | 0.7% | Jun 6, 2024 | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows n... |
| CVE-2024-5256 | MEDIUM | 4.3 | 0.4% | Jun 6, 2024 | Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows ne... |
| CVE-2024-5127 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free pla... |
| CVE-2024-4941 | HIGH | 7.5 | 0.8% | Jun 6, 2024 | A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability a... |
| CVE-2024-4889 | HIGH | 7.2 | 0.9% | Jun 6, 2024 | A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated ... |
| CVE-2024-4325 | HIGH | 8.6 | 37.4% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now