2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31214 | CRITICAL | 9.6 | 17.6% | Apr 10, 2024 | Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded th... |
| CVE-2024-3568 | CRITICAL | 9.6 | 2.1% | Apr 10, 2024 | The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data... |
| CVE-2024-3383 | CRITICAL | 9.1 | 0.6% | Apr 10, 2024 | A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agent... |
| CVE-2024-3098 | CRITICAL | 9.8 | 1.0% | Apr 10, 2024 | A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eva... |
| CVE-2024-3025 | CRITICAL | 9.9 | 1.0% | Apr 10, 2024 | mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input... |
| CVE-2024-2952 | CRITICAL | 9.8 | 1.3% | Apr 10, 2024 | BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerabilit... |
| CVE-2024-2221 | CRITICAL | 9.8 | 1.8% | Apr 10, 2024 | qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTIO... |
| CVE-2024-2195 | CRITICAL | 9.8 | 1.8% | Apr 10, 2024 | A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the... |
| CVE-2024-2029 | CRITICAL | 9.8 | 2.9% | Apr 10, 2024 | A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioTo... |
| CVE-2024-1741 | CRITICAL | 9.1 | 0.6% | Apr 10, 2024 | lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify... |
| CVE-2024-1740 | CRITICAL | 9.1 | 0.6% | Apr 10, 2024 | In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, crea... |
| CVE-2024-1643 | CRITICAL | 9.1 | 0.7% | Apr 10, 2024 | By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read a... |
| CVE-2024-1600 | CRITICAL | 9.3 | 31.1% | Apr 10, 2024 | A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/pe... |
| CVE-2024-1520 | CRITICAL | 9.8 | 48.2% | Apr 10, 2024 | An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui applicatio... |
| CVE-2024-1511 | CRITICAL | 9.8 | 1.0% | Apr 10, 2024 | The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of us... |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.9% | Apr 10, 2024 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d... |
| CVE-2024-23080 | CRITICAL | 9.1 | 1.0% | Apr 10, 2024 | Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::... |
| CVE-2024-20758 | CRITICAL | 9 | 1.4% | Apr 10, 2024 | Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validati... |
| CVE-2024-3535 | CRITICAL | 9.8 | 1.1% | Apr 10, 2024 | A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. This affects an ... |
| CVE-2024-3534 | CRITICAL | 9.8 | 1.1% | Apr 10, 2024 | A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by... |
| CVE-2024-3120 | CRITICAL | 9.8 | 1.8% | Apr 10, 2024 | A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bound... |
| CVE-2024-3119 | CRITICAL | 9.8 | 1.8% | Apr 10, 2024 | A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and... |
| CVE-2024-3214 | CRITICAL | 9.8 | 0.8% | Apr 9, 2024 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and includin... |
| CVE-2024-3136 | CRITICAL | 9.8 | 5.0% | Apr 9, 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3... |
| CVE-2024-2804 | CRITICAL | 9.8 | 0.7% | Apr 9, 2024 | The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now