2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5736HIGH7.5Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to a...
CVE-2024-5735HIGH7.5Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised atta...
CVE-2024-30135HIGH7.5HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot ...
CVE-2024-39350HIGH7.5A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-m...
CVE-2024-39348HIGH7.5Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before...
CVE-2024-30111HIGH7.5HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app ca...
CVE-2024-39351HIGH7.2A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is ...
CVE-2024-39708HIGH7An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096...
CVE-2024-4395HIGH7.8The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local...
CVE-2024-39134HIGH7.5A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_f...
CVE-2024-36074HIGH7.2Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera...
CVE-2024-36073HIGH7.2Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera...
CVE-2024-39207HIGH8.2lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.
CVE-2024-39130HIGH7.5A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the fun...
CVE-2024-38523HIGH7.5Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authenti...
CVE-2024-6250HIGH7.5An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint ...
CVE-2024-6139HIGH7.3A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability...
CVE-2024-6090HIGH7.5A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other ...
CVE-2024-6085HIGH8.6A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerabilit...
CVE-2024-6038HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt....
CVE-2024-5979HIGH7.5In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class ...
CVE-2024-5885HIGH8.6stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not p...
CVE-2024-5824HIGH7.4A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an atta...
CVE-2024-5820HIGH8.8An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious websit...
CVE-2024-4578HIGH8.4This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now