2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10720MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t...
CVE-2024-10719MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ...
CVE-2024-10707MEDIUM6.5gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the...
CVE-2024-10481MEDIUM6.5A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host...
CVE-2024-10457MEDIUM6.5Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito...
CVE-2024-10366MEDIUM6.5An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ...
CVE-2024-10363MEDIUM5.4In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ...
CVE-2024-10359MEDIUM4.6In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca...
CVE-2024-10330MEDIUM6.5In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associa...
CVE-2024-10274MEDIUM6.5An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequ...
CVE-2024-10273MEDIUM6.5In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify...
CVE-2024-10047MEDIUM5.3parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can l...
CVE-2024-10019MEDIUM6.7A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a...
CVE-2024-0640MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerabilit...
CVE-2024-0245MEDIUM5.5A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln...
CVE-2024-54016MEDIUM4.3Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue...
CVE-2024-55009MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and...
CVE-2024-7631MEDIUM4.3A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/re...
CVE-2024-25132MEDIUM4.3A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshi...
CVE-2024-53970MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-53969MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-53968MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-53967MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-45644MEDIUM4.7IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical...
CVE-2024-50629MEDIUM5.3Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now