2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21825CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functiona...
CVE-2024-21802CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2...
CVE-2024-1890MEDIUM5.4Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote att...
CVE-2024-1889HIGH8.8Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability cou...
CVE-2024-1886HIGH8.8 This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
CVE-2024-1885CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
CVE-2024-1878HIGH8.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t...
CVE-2024-1877HIGH8.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected b...
CVE-2024-1876CRITICAL9.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected...
CVE-2024-1875HIGH8.8A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affec...
CVE-2024-1871MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affect...
CVE-2024-1758HIGH8.1The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2024-1735CRITICAL9.1A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messag...
CVE-2024-1710HIGH8.8The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2024-1622HIGH7.5Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too q...
CVE-2024-1436MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, S...
CVE-2024-1165MEDIUM6.5The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,...
CVE-2024-0798MEDIUM6.5A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete ...
CVE-2024-0455HIGH7.5The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin...
CVE-2024-0440MEDIUM6.5Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protoco...
CVE-2024-0439HIGH8.8As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience fo...
CVE-2024-0436MEDIUM5.9Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password ...
CVE-2024-0435MEDIUM5.4User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page lo...
CVE-2024-0387MEDIUM6.5The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An atta...
CVE-2024-0243HIGH8.1With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now