2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53349 | HIGH | 7.4 | 0.4% | Mar 21, 2025 | Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal... |
| CVE-2024-53348 | HIGH | 7.4 | 0.3% | Mar 21, 2025 | LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati... |
| CVE-2024-57490 | HIGH | 7.7 | 0.4% | Mar 21, 2025 | Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ... |
| CVE-2024-13903 | HIGH | 7.5 | 0.7% | Mar 21, 2025 | A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne... |
| CVE-2024-54551 | HIGH | 7.5 | 0.6% | Mar 21, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac... |
| CVE-2024-44305 | HIGH | 7.8 | 0.1% | Mar 21, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t... |
| CVE-2024-44199 | HIGH | 7.1 | 0.2% | Mar 21, 2025 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may... |
| CVE-2024-57440 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr... |
| CVE-2024-13921 | HIGH | 7.2 | 0.6% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio... |
| CVE-2024-9920 | HIGH | 8.8 | 1.2% | Mar 20, 2025 | In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ... |
| CVE-2024-9919 | HIGH | 8.4 | 0.3% | Mar 20, 2025 | A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth... |
| CVE-2024-9847 | HIGH | 8 | 0.3% | Mar 20, 2025 | FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable... |
| CVE-2024-9606 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerabi... |
| CVE-2024-9597 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attac... |
| CVE-2024-9439 | HIGH | 8.8 | 1.1% | Mar 20, 2025 | SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers ... |
| CVE-2024-9437 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in... |
| CVE-2024-9431 | HIGH | 8.8 | 0.6% | Mar 20, 2025 | In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After loggin... |
| CVE-2024-9415 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th... |
| CVE-2024-9363 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den... |
| CVE-2024-9362 | HIGH | 7.5 | 4.2% | Mar 20, 2025 | An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerabilit... |
| CVE-2024-9340 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause exces... |
| CVE-2024-9229 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated a... |
| CVE-2024-9216 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to ... |
| CVE-2024-9099 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro... |
| CVE-2024-9096 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now