2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10330 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associa... |
| CVE-2024-10274 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequ... |
| CVE-2024-10273 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify... |
| CVE-2024-10047 | MEDIUM | 5.3 | 1.0% | Mar 20, 2025 | parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can l... |
| CVE-2024-10019 | MEDIUM | 6.7 | 0.8% | Mar 20, 2025 | A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a... |
| CVE-2024-0640 | MEDIUM | 4.8 | 0.2% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerabilit... |
| CVE-2024-0245 | MEDIUM | 5.5 | 0.2% | Mar 20, 2025 | A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln... |
| CVE-2024-54016 | MEDIUM | 4.3 | 0.6% | Mar 20, 2025 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue... |
| CVE-2024-55009 | MEDIUM | 6.1 | 0.4% | Mar 19, 2025 | A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and... |
| CVE-2024-7631 | MEDIUM | 4.3 | 0.5% | Mar 19, 2025 | A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/re... |
| CVE-2024-25132 | MEDIUM | 4.3 | 0.3% | Mar 19, 2025 | A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshi... |
| CVE-2024-53970 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-53969 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53968 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53967 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-45644 | MEDIUM | 4.7 | 0.3% | Mar 19, 2025 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical... |
| CVE-2024-50629 | MEDIUM | 5.3 | 27.0% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1... |
| CVE-2024-10445 | MEDIUM | 5.3 | 0.4% | Mar 19, 2025 | Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653... |
| CVE-2024-57151 | MEDIUM | 6.8 | 0.4% | Mar 18, 2025 | SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via... |
| CVE-2024-57170 | MEDIUM | 6.5 | 0.8% | Mar 18, 2025 | SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" paramete... |
| CVE-2024-49822 | MEDIUM | 4.1 | 0.3% | Mar 18, 2025 | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authentica... |
| CVE-2024-44314 | MEDIUM | 6.5 | 0.3% | Mar 18, 2025 | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthor... |
| CVE-2024-41975 | MEDIUM | 5.3 | 0.4% | Mar 18, 2025 | An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs p... |
| CVE-2024-54565 | MEDIUM | 6.2 | 0.2% | Mar 17, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access se... |
| CVE-2024-54559 | MEDIUM | 5.5 | 0.2% | Mar 17, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access se... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now