2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32026 | CRITICAL | 9.8 | 3.0% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_g... |
| CVE-2024-32025 | CRITICAL | 9.1 | 2.5% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_... |
| CVE-2024-32022 | CRITICAL | 9.8 | 3.1% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_g... |
| CVE-2024-3871 | CRITICAL | 9.8 | 1.7% | Apr 16, 2024 | The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements mul... |
| CVE-2024-3573 | CRITICAL | 9.3 | 0.7% | Apr 16, 2024 | mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass ... |
| CVE-2024-3271 | CRITICAL | 9.8 | 2.9% | Apr 16, 2024 | A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func... |
| CVE-2024-2912 | CRITICAL | 10 | 1.5% | Apr 16, 2024 | An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi... |
| CVE-2024-2083 | CRITICAL | 9.9 | 39.1% | Apr 16, 2024 | A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo... |
| CVE-2024-1739 | CRITICAL | 9.1 | 0.6% | Apr 16, 2024 | lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu... |
| CVE-2024-1601 | CRITICAL | 9.8 | 40.4% | Apr 16, 2024 | An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al... |
| CVE-2024-0404 | CRITICAL | 9.1 | 0.8% | Apr 16, 2024 | A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,... |
| CVE-2024-31650 | CRITICAL | 9.6 | 0.8% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-28557 | CRITICAL | 9.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr... |
| CVE-2024-28556 | CRITICAL | 9.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr... |
| CVE-2024-24486 | CRITICAL | 9.1 | 0.6% | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the... |
| CVE-2024-28056 | CRITICAL | 9.8 | 1.7% | Apr 15, 2024 | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify ... |
| CVE-2024-3797 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerab... |
| CVE-2024-3781 | CRITICAL | 9.1 | 1.2% | Apr 15, 2024 | Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory... |
| CVE-2024-23486 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthe... |
| CVE-2024-3701 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows ... |
| CVE-2024-32430 | CRITICAL | 9.8 | 0.4% | Apr 15, 2024 | Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8... |
| CVE-2024-32128 | CRITICAL | 9.3 | 1.7% | Apr 15, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna ... |
| CVE-2024-3770 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vul... |
| CVE-2024-3777 | CRITICAL | 9.8 | 0.7% | Apr 15, 2024 | The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset... |
| CVE-2024-3769 | CRITICAL | 9.8 | 0.9% | Apr 15, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now