2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3515MEDIUM6.5Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap co...
CVE-2024-3157CRITICAL9.6Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had co...
CVE-2024-31464MEDIUM4.9XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9...
CVE-2024-31386MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Defaul...
CVE-2024-28345MEDIUM5.5An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpo...
CVE-2024-28344LOW3.1An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability al...
CVE-2024-23077HIGH7.5JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.jav...
CVE-2024-31944MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This...
CVE-2024-31943MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affect...
CVE-2024-31461CRITICAL9.1Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior ...
CVE-2024-31242MEDIUM5.3Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
CVE-2024-31230MEDIUM5.3Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affec...
CVE-2024-31214CRITICAL9.6Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded th...
CVE-2024-3570MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm rep...
CVE-2024-3569HIGH7.5A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is runn...
CVE-2024-3568CRITICAL9.6The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data...
CVE-2024-3388MEDIUM5A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to ...
CVE-2024-3387MEDIUM5.9A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a me...
CVE-2024-3386MEDIUM5.3An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclus...
CVE-2024-3385HIGH7.5A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based f...
CVE-2024-3384HIGH7.5A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receivin...
CVE-2024-3383CRITICAL9.1A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agent...
CVE-2024-3382HIGH7.5A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets t...
CVE-2024-3283HIGH7.2A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin role...
CVE-2024-3101HIGH7.2In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by dea...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now