2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3573 | CRITICAL | 9.3 | 0.7% | Apr 16, 2024 | mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass ... |
| CVE-2024-3271 | CRITICAL | 9.8 | 2.9% | Apr 16, 2024 | A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func... |
| CVE-2024-2912 | CRITICAL | 10 | 1.5% | Apr 16, 2024 | An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi... |
| CVE-2024-2083 | CRITICAL | 9.9 | 39.1% | Apr 16, 2024 | A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo... |
| CVE-2024-1739 | CRITICAL | 9.1 | 0.6% | Apr 16, 2024 | lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu... |
| CVE-2024-1601 | CRITICAL | 9.8 | 40.4% | Apr 16, 2024 | An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al... |
| CVE-2024-0404 | CRITICAL | 9.1 | 0.8% | Apr 16, 2024 | A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,... |
| CVE-2024-31650 | CRITICAL | 9.6 | 0.8% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-28557 | CRITICAL | 9.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr... |
| CVE-2024-28556 | CRITICAL | 9.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr... |
| CVE-2024-24486 | CRITICAL | 9.1 | 0.6% | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the... |
| CVE-2024-28056 | CRITICAL | 9.8 | 1.7% | Apr 15, 2024 | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify ... |
| CVE-2024-3797 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerab... |
| CVE-2024-3781 | CRITICAL | 9.1 | 1.2% | Apr 15, 2024 | Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory... |
| CVE-2024-23486 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthe... |
| CVE-2024-3701 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows ... |
| CVE-2024-32430 | CRITICAL | 9.8 | 0.4% | Apr 15, 2024 | Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8... |
| CVE-2024-32128 | CRITICAL | 9.3 | 1.7% | Apr 15, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna ... |
| CVE-2024-3770 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vul... |
| CVE-2024-3777 | CRITICAL | 9.8 | 0.7% | Apr 15, 2024 | The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset... |
| CVE-2024-3769 | CRITICAL | 9.8 | 0.9% | Apr 15, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un... |
| CVE-2024-3768 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue... |
| CVE-2024-29844 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to p... |
| CVE-2024-29836 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-3765 | CRITICAL | 9.8 | 1.2% | Apr 14, 2024 | A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, A... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now