2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10720 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t... |
| CVE-2024-10719 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ... |
| CVE-2024-10707 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the... |
| CVE-2024-10481 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host... |
| CVE-2024-10457 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito... |
| CVE-2024-10366 | MEDIUM | 6.5 | 0.3% | Mar 20, 2025 | An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ... |
| CVE-2024-10363 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ... |
| CVE-2024-10359 | MEDIUM | 4.6 | 0.3% | Mar 20, 2025 | In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca... |
| CVE-2024-10330 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associa... |
| CVE-2024-10274 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequ... |
| CVE-2024-10273 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify... |
| CVE-2024-10047 | MEDIUM | 5.3 | 1.0% | Mar 20, 2025 | parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can l... |
| CVE-2024-10019 | MEDIUM | 6.7 | 0.8% | Mar 20, 2025 | A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a... |
| CVE-2024-0640 | MEDIUM | 4.8 | 0.2% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerabilit... |
| CVE-2024-0245 | MEDIUM | 5.5 | 0.2% | Mar 20, 2025 | A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln... |
| CVE-2024-54016 | MEDIUM | 4.3 | 0.6% | Mar 20, 2025 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue... |
| CVE-2024-55009 | MEDIUM | 6.1 | 0.4% | Mar 19, 2025 | A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and... |
| CVE-2024-7631 | MEDIUM | 4.3 | 0.5% | Mar 19, 2025 | A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/re... |
| CVE-2024-25132 | MEDIUM | 4.3 | 0.3% | Mar 19, 2025 | A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshi... |
| CVE-2024-53970 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-53969 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53968 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53967 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-45644 | MEDIUM | 4.7 | 0.3% | Mar 19, 2025 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical... |
| CVE-2024-50629 | MEDIUM | 5.3 | 27.0% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now