2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4263 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with onl... |
| CVE-2024-4223 | CRITICAL | 9.8 | 0.5% | May 16, 2024 | The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due ... |
| CVE-2024-4181 | HIGH | 8.8 | 2.1% | May 16, 2024 | A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the ... |
| CVE-2024-4078 | CRITICAL | 9.8 | 0.9% | May 16, 2024 | A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code exe... |
| CVE-2024-3887 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form ... |
| CVE-2024-3851 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper valida... |
| CVE-2024-3848 | HIGH | 7.5 | 43.3% | May 16, 2024 | A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously address... |
| CVE-2024-3435 | HIGH | 8.4 | 0.8% | May 16, 2024 | A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affectin... |
| CVE-2024-3403 | HIGH | 7.5 | 1.1% | May 16, 2024 | imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read a... |
| CVE-2024-3126 | HIGH | 8.4 | 1.3% | May 16, 2024 | A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application,... |
| CVE-2024-30309 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ... |
| CVE-2024-30308 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ... |
| CVE-2024-30307 | HIGH | 7.8 | 0.3% | May 16, 2024 | Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2024-30298 | MEDIUM | 5.5 | 0.3% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead ... |
| CVE-2024-30297 | HIGH | 7.8 | 0.3% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2024-30296 | HIGH | 7.8 | 0.3% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2024-30295 | HIGH | 7.8 | 0.4% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result i... |
| CVE-2024-30294 | HIGH | 7.8 | 0.4% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result... |
| CVE-2024-30293 | HIGH | 7.8 | 0.4% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could resul... |
| CVE-2024-30282 | HIGH | 7.8 | 0.3% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2024-30281 | MEDIUM | 5.5 | 0.3% | May 16, 2024 | Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that coul... |
| CVE-2024-30275 | HIGH | 7.8 | 0.4% | May 16, 2024 | Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitra... |
| CVE-2024-30274 | HIGH | 7.8 | 0.3% | May 16, 2024 | Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2024-2366 | CRITICAL | 9 | 0.7% | May 16, 2024 | A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall... |
| CVE-2024-2361 | CRITICAL | 9.6 | 0.6% | May 16, 2024 | A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now