2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4263MEDIUM5.4A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with onl...
CVE-2024-4223CRITICAL9.8The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due ...
CVE-2024-4181HIGH8.8A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the ...
CVE-2024-4078CRITICAL9.8A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code exe...
CVE-2024-3887MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form ...
CVE-2024-3851MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper valida...
CVE-2024-3848HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously address...
CVE-2024-3435HIGH8.4A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affectin...
CVE-2024-3403HIGH7.5imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read a...
CVE-2024-3126HIGH8.4A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application,...
CVE-2024-30309MEDIUM5.5Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ...
CVE-2024-30308MEDIUM5.5Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ...
CVE-2024-30307HIGH7.8Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2024-30298MEDIUM5.5Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead ...
CVE-2024-30297HIGH7.8Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ar...
CVE-2024-30296HIGH7.8Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ar...
CVE-2024-30295HIGH7.8Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result i...
CVE-2024-30294HIGH7.8Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result...
CVE-2024-30293HIGH7.8Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could resul...
CVE-2024-30282HIGH7.8Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ar...
CVE-2024-30281MEDIUM5.5Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that coul...
CVE-2024-30275HIGH7.8Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitra...
CVE-2024-30274HIGH7.8Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2024-2366CRITICAL9A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall...
CVE-2024-2361CRITICAL9.6A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now