2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32023MEDIUM5.3Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p...
CVE-2024-32022CRITICAL9.8Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_g...
CVE-2024-31451MEDIUM5.3DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.p...
CVE-2024-30256MEDIUM6.4Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forger...
CVE-2024-3869MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ...
CVE-2024-3672MEDIUM5.4The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' sh...
CVE-2024-3243MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing c...
CVE-2024-3067HIGH7.2The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve...
CVE-2024-3367MEDIUM5.5Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to...
CVE-2024-3867MEDIUM6.1The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-1357MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-3872MEDIUM6.5Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain d...
CVE-2024-3871CRITICAL9.8The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements mul...
CVE-2024-32634MEDIUM6.1In huge memory get unmapped area check, code can never be reached because of a logical contradiction.
CVE-2024-32633MEDIUM4An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way.
CVE-2024-32632MEDIUM6.6A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access
CVE-2024-32631HIGH8Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
CVE-2024-32625MEDIUM5.8In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computa...
CVE-2024-32557MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E...
CVE-2024-22262HIGH8.1Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf...
CVE-2024-31784MEDIUM6.1An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary co...
CVE-2024-31783MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive infor...
CVE-2024-31634MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbit...
CVE-2024-3575MEDIUM6.1Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
CVE-2024-3574HIGH7.5In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server auth...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now