2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32023 | MEDIUM | 5.3 | 0.7% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p... |
| CVE-2024-32022 | CRITICAL | 9.8 | 3.1% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_g... |
| CVE-2024-31451 | MEDIUM | 5.3 | 0.6% | Apr 16, 2024 | DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.p... |
| CVE-2024-30256 | MEDIUM | 6.4 | 0.4% | Apr 16, 2024 | Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forger... |
| CVE-2024-3869 | MEDIUM | 4.3 | 0.5% | Apr 16, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ... |
| CVE-2024-3672 | MEDIUM | 5.4 | 0.3% | Apr 16, 2024 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' sh... |
| CVE-2024-3243 | MEDIUM | 4.3 | 0.4% | Apr 16, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing c... |
| CVE-2024-3067 | HIGH | 7.2 | 0.7% | Apr 16, 2024 | The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve... |
| CVE-2024-3367 | MEDIUM | 5.5 | 0.3% | Apr 16, 2024 | Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to... |
| CVE-2024-3867 | MEDIUM | 6.1 | 0.8% | Apr 16, 2024 | The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad... |
| CVE-2024-1357 | MEDIUM | 5.4 | 0.4% | Apr 16, 2024 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-3872 | MEDIUM | 6.5 | 0.5% | Apr 16, 2024 | Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain d... |
| CVE-2024-3871 | CRITICAL | 9.8 | 1.7% | Apr 16, 2024 | The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements mul... |
| CVE-2024-32634 | MEDIUM | 6.1 | 0.3% | Apr 16, 2024 | In huge memory get unmapped area check, code can never be reached because of a logical contradiction. |
| CVE-2024-32633 | MEDIUM | 4 | 0.2% | Apr 16, 2024 | An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way. |
| CVE-2024-32632 | MEDIUM | 6.6 | 0.2% | Apr 16, 2024 | A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access |
| CVE-2024-32631 | HIGH | 8 | 0.3% | Apr 16, 2024 | Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations. |
| CVE-2024-32625 | MEDIUM | 5.8 | 0.4% | Apr 16, 2024 | In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computa... |
| CVE-2024-32557 | MEDIUM | 5.4 | 0.3% | Apr 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E... |
| CVE-2024-22262 | HIGH | 8.1 | 1.2% | Apr 16, 2024 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf... |
| CVE-2024-31784 | MEDIUM | 6.1 | 0.3% | Apr 16, 2024 | An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary co... |
| CVE-2024-31783 | MEDIUM | 6.1 | 0.4% | Apr 16, 2024 | Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive infor... |
| CVE-2024-31634 | MEDIUM | 6.1 | 0.6% | Apr 16, 2024 | Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbit... |
| CVE-2024-3575 | MEDIUM | 6.1 | 0.4% | Apr 16, 2024 | Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb |
| CVE-2024-3574 | HIGH | 7.5 | 0.6% | Apr 16, 2024 | In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server auth... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now