2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-30534CRITICAL9.8Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Ca...
CVE-2024-5774CRITICAL9.8A vulnerability has been found in SourceCodester Stock Management System 1.0 and classified as critical. Affected by thi...
CVE-2024-5773CRITICAL9.8A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affec...
CVE-2024-5772CRITICAL9.8A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. ...
CVE-2024-4146CRITICAL9.8In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to a...
CVE-2024-37407CRITICAL9.1Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enable...
CVE-2024-37388CRITICAL9.1An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers...
CVE-2024-5745CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affecte...
CVE-2024-30163CRITICAL9.8Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\...
CVE-2024-36673CRITICAL9.8Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerabi...
CVE-2024-5733CRITICAL9.8A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects...
CVE-2024-5732CRITICAL9.8A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects...
CVE-2024-4620CRITICAL9.8The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify u...
CVE-2024-37385CRITICAL9.8Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_ide...
CVE-2024-24192CRITICAL9.1robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-inser...
CVE-2024-32752CRITICAL9.1The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with I...
CVE-2024-22074CRITICAL9.8Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5....
CVE-2024-5328CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the e...
CVE-2024-4320CRITICAL9.8A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui app...
CVE-2024-3429CRITICAL9.8A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_en...
CVE-2024-3408CRITICAL9.8man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper...
CVE-2024-3322CRITICAL9.8A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui,...
CVE-2024-3234CRITICAL9.8The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio...
CVE-2024-3166CRITICAL9.6A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application ...
CVE-2024-2624CRITICAL9.8A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically w...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now