2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5736 | HIGH | 7.5 | 1.2% | Jun 28, 2024 | Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to a... |
| CVE-2024-5735 | HIGH | 7.5 | 1.5% | Jun 28, 2024 | Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised atta... |
| CVE-2024-30135 | HIGH | 7.5 | 0.3% | Jun 28, 2024 | HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot ... |
| CVE-2024-39350 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-m... |
| CVE-2024-39348 | HIGH | 7.5 | 0.3% | Jun 28, 2024 | Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before... |
| CVE-2024-30111 | HIGH | 7.5 | 0.3% | Jun 28, 2024 | HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app ca... |
| CVE-2024-39351 | HIGH | 7.2 | 1.5% | Jun 28, 2024 | A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is ... |
| CVE-2024-39708 | HIGH | 7 | 0.2% | Jun 28, 2024 | An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096... |
| CVE-2024-4395 | HIGH | 7.8 | 0.2% | Jun 27, 2024 | The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local... |
| CVE-2024-39134 | HIGH | 7.5 | 0.6% | Jun 27, 2024 | A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_f... |
| CVE-2024-36074 | HIGH | 7.2 | 0.8% | Jun 27, 2024 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera... |
| CVE-2024-36073 | HIGH | 7.2 | 0.8% | Jun 27, 2024 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera... |
| CVE-2024-39207 | HIGH | 8.2 | 0.5% | Jun 27, 2024 | lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function. |
| CVE-2024-39130 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the fun... |
| CVE-2024-38523 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authenti... |
| CVE-2024-6250 | HIGH | 7.5 | 2.0% | Jun 27, 2024 | An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint ... |
| CVE-2024-6139 | HIGH | 7.3 | 0.5% | Jun 27, 2024 | A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability... |
| CVE-2024-6090 | HIGH | 7.5 | 0.9% | Jun 27, 2024 | A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other ... |
| CVE-2024-6085 | HIGH | 8.6 | 0.6% | Jun 27, 2024 | A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerabilit... |
| CVE-2024-6038 | HIGH | 7.5 | 0.7% | Jun 27, 2024 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt.... |
| CVE-2024-5979 | HIGH | 7.5 | 0.8% | Jun 27, 2024 | In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class ... |
| CVE-2024-5885 | HIGH | 8.6 | 0.6% | Jun 27, 2024 | stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not p... |
| CVE-2024-5824 | HIGH | 7.4 | 0.4% | Jun 27, 2024 | A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an atta... |
| CVE-2024-5820 | HIGH | 8.8 | 0.8% | Jun 27, 2024 | An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious websit... |
| CVE-2024-4578 | HIGH | 8.4 | 0.5% | Jun 27, 2024 | This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now