2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-32026CRITICAL9.8Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_g...
CVE-2024-32025CRITICAL9.1Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_...
CVE-2024-32022CRITICAL9.8Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_g...
CVE-2024-3871CRITICAL9.8The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements mul...
CVE-2024-3573CRITICAL9.3mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass ...
CVE-2024-3271CRITICAL9.8A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func...
CVE-2024-2912CRITICAL10An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi...
CVE-2024-2083CRITICAL9.9A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo...
CVE-2024-1739CRITICAL9.1lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu...
CVE-2024-1601CRITICAL9.8An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al...
CVE-2024-0404CRITICAL9.1A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,...
CVE-2024-31650CRITICAL9.6A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-28557CRITICAL9.8SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr...
CVE-2024-28556CRITICAL9.8SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr...
CVE-2024-24486CRITICAL9.1An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the...
CVE-2024-28056CRITICAL9.8Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify ...
CVE-2024-3797CRITICAL9.8A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerab...
CVE-2024-3781CRITICAL9.1Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory...
CVE-2024-23486CRITICAL9.8Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthe...
CVE-2024-3701CRITICAL9.8The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows ...
CVE-2024-32430CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8...
CVE-2024-32128CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna ...
CVE-2024-3770CRITICAL9.8A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vul...
CVE-2024-3777CRITICAL9.8The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset...
CVE-2024-3769CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now