2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2362 | CRITICAL | 9.1 | 1.1% | Jun 6, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper ... |
| CVE-2024-2360 | CRITICAL | 9.8 | 1.9% | Jun 6, 2024 | parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient... |
| CVE-2024-2359 | CRITICAL | 9.8 | 1.2% | Jun 6, 2024 | A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and exe... |
| CVE-2024-1881 | CRITICAL | 9.8 | 1.4% | Jun 6, 2024 | AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements us... |
| CVE-2024-1873 | CRITICAL | 9.1 | 13.4% | Jun 6, 2024 | parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database`... |
| CVE-2024-5482 | CRITICAL | 9.8 | 0.7% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui app... |
| CVE-2024-5452 | CRITICAL | 9.8 | 26.5% | Jun 6, 2024 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to im... |
| CVE-2024-3104 | CRITICAL | 9.8 | 1.0% | Jun 6, 2024 | A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment varia... |
| CVE-2024-3033 | CRITICAL | 9.4 | 0.6% | Jun 6, 2024 | An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/... |
| CVE-2024-36736 | CRITICAL | 9.8 | 0.6% | Jun 6, 2024 | An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same d... |
| CVE-2024-34832 | CRITICAL | 9.8 | 5.0% | Jun 6, 2024 | Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf... |
| CVE-2024-5675 | CRITICAL | 9.8 | 0.6% | Jun 6, 2024 | Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This... |
| CVE-2024-36779 | CRITICAL | 9.8 | 0.6% | Jun 6, 2024 | Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php. |
| CVE-2024-36394 | CRITICAL | 9.8 | 1.1% | Jun 6, 2024 | SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2024-36393 | CRITICAL | 9.8 | 0.4% | Jun 6, 2024 | SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2024-4177 | CRITICAL | 9.8 | 0.4% | Jun 6, 2024 | A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to ca... |
| CVE-2024-5153 | CRITICAL | 9.8 | 1.0% | Jun 6, 2024 | The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl... |
| CVE-2024-5653 | CRITICAL | 9.8 | 0.5% | Jun 5, 2024 | A vulnerability, which was classified as critical, has been found in Chanjet Smooth T+system 3.5. This issue affects som... |
| CVE-2024-5171 | CRITICAL | 9.8 | 1.3% | Jun 5, 2024 | Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be rea... |
| CVE-2024-5184 | CRITICAL | 9.1 | 0.5% | Jun 5, 2024 | The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious ... |
| CVE-2024-24790 | CRITICAL | 9.8 | 2.0% | Jun 5, 2024 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning f... |
| CVE-2024-5526 | CRITICAL | 9.1 | 0.4% | Jun 5, 2024 | Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simple... |
| CVE-2024-4295 | CRITICAL | 9.8 | 10.2% | Jun 5, 2024 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in... |
| CVE-2024-5262 | CRITICAL | 9.8 | 0.6% | Jun 5, 2024 | Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows re... |
| CVE-2024-5636 | CRITICAL | 9.8 | 0.7% | Jun 5, 2024 | A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now