2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-10835CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri...
CVE-2024-10834CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ...
CVE-2024-10833CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u...
CVE-2024-10831CRITICAL9.1In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu...
CVE-2024-10553CRITICAL9.8A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitra...
CVE-2024-10361CRITICAL9.1An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /ap...
CVE-2024-10264CRITICAL9.8HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistenci...
CVE-2024-10190CRITICAL9.8Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability ...
CVE-2024-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incu...
CVE-2024-12016CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM ...
CVE-2024-57061CRITICAL9.8An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via ...
CVE-2024-13442CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2024-13790CRITICAL9.8The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ...
CVE-2024-13410CRITICAL9.8The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ...
CVE-2024-12922CRITICAL9.8The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ...
CVE-2024-11131CRITICAL9.8A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar...
CVE-2024-10442CRITICAL10Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0...
CVE-2024-10441CRITICAL9.8Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before...
CVE-2024-56347CRITICAL9.6IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma...
CVE-2024-56346CRITICAL10IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improp...
CVE-2024-57169CRITICAL9.8A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability...
CVE-2024-8997CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Confi...
CVE-2024-23943CRITICAL9.1An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical funct...
CVE-2024-12992CRITICAL9.8Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This ...
CVE-2024-55594CRITICAL9.8An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now