2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10835 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri... |
| CVE-2024-10834 | CRITICAL | 9.1 | 0.6% | Mar 20, 2025 | eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ... |
| CVE-2024-10833 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u... |
| CVE-2024-10831 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu... |
| CVE-2024-10553 | CRITICAL | 9.8 | 1.4% | Mar 20, 2025 | A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitra... |
| CVE-2024-10361 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /ap... |
| CVE-2024-10264 | CRITICAL | 9.8 | 0.9% | Mar 20, 2025 | HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistenci... |
| CVE-2024-10190 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability ... |
| CVE-2024-47552 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incu... |
| CVE-2024-12016 | CRITICAL | 9.8 | 0.4% | Mar 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM ... |
| CVE-2024-57061 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via ... |
| CVE-2024-13442 | CRITICAL | 9.8 | 0.4% | Mar 19, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2024-13790 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ... |
| CVE-2024-13410 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ... |
| CVE-2024-12922 | CRITICAL | 9.8 | 0.5% | Mar 19, 2025 | The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ... |
| CVE-2024-11131 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar... |
| CVE-2024-10442 | CRITICAL | 10 | 1.3% | Mar 19, 2025 | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0... |
| CVE-2024-10441 | CRITICAL | 9.8 | 1.1% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before... |
| CVE-2024-56347 | CRITICAL | 9.6 | 0.9% | Mar 18, 2025 | IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma... |
| CVE-2024-56346 | CRITICAL | 10 | 1.1% | Mar 18, 2025 | IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improp... |
| CVE-2024-57169 | CRITICAL | 9.8 | 0.9% | Mar 18, 2025 | A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability... |
| CVE-2024-8997 | CRITICAL | 9.8 | 0.4% | Mar 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Confi... |
| CVE-2024-23943 | CRITICAL | 9.1 | 0.6% | Mar 18, 2025 | An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical funct... |
| CVE-2024-12992 | CRITICAL | 9.8 | 1.3% | Mar 17, 2025 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This ... |
| CVE-2024-55594 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now