2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-31214CRITICAL9.6Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded th...
CVE-2024-3568CRITICAL9.6The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data...
CVE-2024-3383CRITICAL9.1A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agent...
CVE-2024-3098CRITICAL9.8A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eva...
CVE-2024-3025CRITICAL9.9mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input...
CVE-2024-2952CRITICAL9.8BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerabilit...
CVE-2024-2221CRITICAL9.8qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTIO...
CVE-2024-2195CRITICAL9.8A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the...
CVE-2024-2029CRITICAL9.8A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioTo...
CVE-2024-1741CRITICAL9.1lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify...
CVE-2024-1740CRITICAL9.1In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, crea...
CVE-2024-1643CRITICAL9.1By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read a...
CVE-2024-1600CRITICAL9.3A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/pe...
CVE-2024-1520CRITICAL9.8An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui applicatio...
CVE-2024-1511CRITICAL9.8The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of us...
CVE-2024-3566CRITICAL9.8A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d...
CVE-2024-23080CRITICAL9.1Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::...
CVE-2024-20758CRITICAL9Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validati...
CVE-2024-3535CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. This affects an ...
CVE-2024-3534CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by...
CVE-2024-3120CRITICAL9.8A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bound...
CVE-2024-3119CRITICAL9.8A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and...
CVE-2024-3214CRITICAL9.8The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and includin...
CVE-2024-3136CRITICAL9.8The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3...
CVE-2024-2804CRITICAL9.8The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now