2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30534 | CRITICAL | 9.8 | 0.4% | Jun 9, 2024 | Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Ca... |
| CVE-2024-5774 | CRITICAL | 9.8 | 0.7% | Jun 9, 2024 | A vulnerability has been found in SourceCodester Stock Management System 1.0 and classified as critical. Affected by thi... |
| CVE-2024-5773 | CRITICAL | 9.8 | 0.7% | Jun 9, 2024 | A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affec... |
| CVE-2024-5772 | CRITICAL | 9.8 | 0.7% | Jun 9, 2024 | A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. ... |
| CVE-2024-4146 | CRITICAL | 9.8 | 0.5% | Jun 8, 2024 | In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to a... |
| CVE-2024-37407 | CRITICAL | 9.1 | 1.0% | Jun 8, 2024 | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enable... |
| CVE-2024-37388 | CRITICAL | 9.1 | 0.5% | Jun 7, 2024 | An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers... |
| CVE-2024-5745 | CRITICAL | 9.8 | 0.9% | Jun 7, 2024 | A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affecte... |
| CVE-2024-30163 | CRITICAL | 9.8 | 8.7% | Jun 7, 2024 | Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\... |
| CVE-2024-36673 | CRITICAL | 9.8 | 0.5% | Jun 7, 2024 | Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerabi... |
| CVE-2024-5733 | CRITICAL | 9.8 | 0.6% | Jun 7, 2024 | A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects... |
| CVE-2024-5732 | CRITICAL | 9.8 | 0.9% | Jun 7, 2024 | A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects... |
| CVE-2024-4620 | CRITICAL | 9.8 | 3.3% | Jun 7, 2024 | The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify u... |
| CVE-2024-37385 | CRITICAL | 9.8 | 1.5% | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_ide... |
| CVE-2024-24192 | CRITICAL | 9.1 | 0.4% | Jun 6, 2024 | robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-inser... |
| CVE-2024-32752 | CRITICAL | 9.1 | 0.6% | Jun 6, 2024 | The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with I... |
| CVE-2024-22074 | CRITICAL | 9.8 | 0.4% | Jun 6, 2024 | Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.... |
| CVE-2024-5328 | CRITICAL | 9.3 | 0.4% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the e... |
| CVE-2024-4320 | CRITICAL | 9.8 | 34.4% | Jun 6, 2024 | A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui app... |
| CVE-2024-3429 | CRITICAL | 9.8 | 28.3% | Jun 6, 2024 | A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_en... |
| CVE-2024-3408 | CRITICAL | 9.8 | 78.0% | Jun 6, 2024 | man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper... |
| CVE-2024-3322 | CRITICAL | 9.8 | 0.7% | Jun 6, 2024 | A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui,... |
| CVE-2024-3234 | CRITICAL | 9.8 | 3.8% | Jun 6, 2024 | The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio... |
| CVE-2024-3166 | CRITICAL | 9.6 | 1.0% | Jun 6, 2024 | A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application ... |
| CVE-2024-2624 | CRITICAL | 9.8 | 1.3% | Jun 6, 2024 | A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically w... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now