2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-2362CRITICAL9.1A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper ...
CVE-2024-2360CRITICAL9.8parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient...
CVE-2024-2359CRITICAL9.8A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and exe...
CVE-2024-1881CRITICAL9.8AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements us...
CVE-2024-1873CRITICAL9.1parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database`...
CVE-2024-5482CRITICAL9.8A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui app...
CVE-2024-5452CRITICAL9.8A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to im...
CVE-2024-3104CRITICAL9.8A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment varia...
CVE-2024-3033CRITICAL9.4An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/...
CVE-2024-36736CRITICAL9.8An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same d...
CVE-2024-34832CRITICAL9.8Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf...
CVE-2024-5675CRITICAL9.8Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This...
CVE-2024-36779CRITICAL9.8Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.
CVE-2024-36394CRITICAL9.8SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-36393CRITICAL9.8SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-4177CRITICAL9.8A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to ca...
CVE-2024-5153CRITICAL9.8The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl...
CVE-2024-5653CRITICAL9.8A vulnerability, which was classified as critical, has been found in Chanjet Smooth T+system 3.5. This issue affects som...
CVE-2024-5171CRITICAL9.8Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be rea...
CVE-2024-5184CRITICAL9.1The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious ...
CVE-2024-24790CRITICAL9.8The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning f...
CVE-2024-5526CRITICAL9.1Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simple...
CVE-2024-4295CRITICAL9.8The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in...
CVE-2024-5262CRITICAL9.8Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows re...
CVE-2024-5636CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now