2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53349HIGH7.4Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53348HIGH7.4LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati...
CVE-2024-57490HIGH7.7Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ...
CVE-2024-13903HIGH7.5A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne...
CVE-2024-54551HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac...
CVE-2024-44305HIGH7.8This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t...
CVE-2024-44199HIGH7.1An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may...
CVE-2024-57440HIGH7.5D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr...
CVE-2024-13921HIGH7.2The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio...
CVE-2024-9920HIGH8.8In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ...
CVE-2024-9919HIGH8.4A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth...
CVE-2024-9847HIGH8FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable...
CVE-2024-9606HIGH7.5In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerabi...
CVE-2024-9597HIGH7.1A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attac...
CVE-2024-9439HIGH8.8SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers ...
CVE-2024-9437HIGH7.5SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in...
CVE-2024-9431HIGH8.8In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After loggin...
CVE-2024-9415HIGH8.8A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th...
CVE-2024-9363HIGH7.5An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den...
CVE-2024-9362HIGH7.5An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerabilit...
CVE-2024-9340HIGH7.5A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause exces...
CVE-2024-9229HIGH7.5A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated a...
CVE-2024-9216HIGH8.1An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to ...
CVE-2024-9099HIGH8.1In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro...
CVE-2024-9096HIGH7.1In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now