2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-11041CRITICAL9.8vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses ...
CVE-2024-10902CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Uplo...
CVE-2024-10901CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que...
CVE-2024-10835CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri...
CVE-2024-10834CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ...
CVE-2024-10833CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u...
CVE-2024-10831CRITICAL9.1In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu...
CVE-2024-10553CRITICAL9.8A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitra...
CVE-2024-10361CRITICAL9.1An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /ap...
CVE-2024-10264CRITICAL9.8HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistenci...
CVE-2024-10190CRITICAL9.8Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability ...
CVE-2024-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incu...
CVE-2024-12016CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM ...
CVE-2024-57061CRITICAL9.8An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via ...
CVE-2024-13442CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2024-13790CRITICAL9.8The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ...
CVE-2024-13410CRITICAL9.8The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ...
CVE-2024-12922CRITICAL9.8The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ...
CVE-2024-11131CRITICAL9.8A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar...
CVE-2024-10442CRITICAL10Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0...
CVE-2024-10441CRITICAL9.8Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before...
CVE-2024-56347CRITICAL9.6IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma...
CVE-2024-56346CRITICAL10IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improp...
CVE-2024-57169CRITICAL9.8A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability...
CVE-2024-8997CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Confi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now