2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-3573CRITICAL9.3mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass ...
CVE-2024-3271CRITICAL9.8A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func...
CVE-2024-2912CRITICAL10An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi...
CVE-2024-2083CRITICAL9.9A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo...
CVE-2024-1739CRITICAL9.1lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu...
CVE-2024-1601CRITICAL9.8An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al...
CVE-2024-0404CRITICAL9.1A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,...
CVE-2024-31650CRITICAL9.6A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-28557CRITICAL9.8SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr...
CVE-2024-28556CRITICAL9.8SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr...
CVE-2024-24486CRITICAL9.1An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the...
CVE-2024-28056CRITICAL9.8Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify ...
CVE-2024-3797CRITICAL9.8A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerab...
CVE-2024-3781CRITICAL9.1Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory...
CVE-2024-23486CRITICAL9.8Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthe...
CVE-2024-3701CRITICAL9.8The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows ...
CVE-2024-32430CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8...
CVE-2024-32128CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna ...
CVE-2024-3770CRITICAL9.8A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vul...
CVE-2024-3777CRITICAL9.8The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset...
CVE-2024-3769CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un...
CVE-2024-3768CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue...
CVE-2024-29844CRITICAL9.8Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to p...
CVE-2024-29836CRITICAL9.8The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-3765CRITICAL9.8A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, A...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now