2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3504MEDIUM6.5An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin c...
CVE-2024-3152HIGH8.8mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoin...
CVE-2024-3104CRITICAL9.8A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment varia...
CVE-2024-3033CRITICAL9.4An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/...
CVE-2024-36745HIGH7.5An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative val...
CVE-2024-36743HIGH7.5An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is proce...
CVE-2024-36737HIGH7.5Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti...
CVE-2024-36736CRITICAL9.8An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same d...
CVE-2024-30375HIGH7.8Luxion KeyShot Viewer KSP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2024-30374HIGH7.8Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-30369HIGH7.8A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows loca...
CVE-2024-30368HIGH8.8A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2024-2914HIGH8.8A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vu...
CVE-2024-1879HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to exe...
CVE-2024-36742HIGH7.5An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (...
CVE-2024-33655HIGH7.5The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by ...
CVE-2024-37156MEDIUM6.1The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is ...
CVE-2024-37152HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access t...
CVE-2024-37150MEDIUM6.5An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to t...
CVE-2024-36399MEDIUM6.3Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer...
CVE-2024-35178HIGH7.5The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that...
CVE-2024-36106MEDIUM4.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enume...
CVE-2024-34832CRITICAL9.8Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf...
CVE-2024-5684HIGH8.8An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface c...
CVE-2024-5675CRITICAL9.8Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now