2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32086 | HIGH | 7.5 | 0.5% | Apr 16, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affect... |
| CVE-2024-3874 | HIGH | 8.8 | 1.3% | Apr 16, 2024 | A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the func... |
| CVE-2024-3865 | HIGH | 8.1 | 0.5% | Apr 16, 2024 | Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-3864 | HIGH | 8.1 | 0.8% | Apr 16, 2024 | Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c... |
| CVE-2024-3858 | HIGH | 7.5 | 0.6% | Apr 16, 2024 | It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F... |
| CVE-2024-3857 | HIGH | 7.8 | 0.2% | Apr 16, 2024 | The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garba... |
| CVE-2024-3856 | HIGH | 8.8 | 0.6% | Apr 16, 2024 | A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulne... |
| CVE-2024-3854 | HIGH | 8.8 | 0.7% | Apr 16, 2024 | In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This ... |
| CVE-2024-3853 | HIGH | 7.5 | 0.4% | Apr 16, 2024 | A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection st... |
| CVE-2024-3852 | HIGH | 7.5 | 0.6% | Apr 16, 2024 | GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects... |
| CVE-2024-3067 | HIGH | 7.2 | 0.7% | Apr 16, 2024 | The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve... |
| CVE-2024-32631 | HIGH | 8 | 0.3% | Apr 16, 2024 | Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations. |
| CVE-2024-22262 | HIGH | 8.1 | 1.2% | Apr 16, 2024 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf... |
| CVE-2024-3574 | HIGH | 7.5 | 0.6% | Apr 16, 2024 | In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server auth... |
| CVE-2024-3572 | HIGH | 7.5 | 0.8% | Apr 16, 2024 | The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for... |
| CVE-2024-3571 | HIGH | 8.8 | 1.9% | Apr 16, 2024 | langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted director... |
| CVE-2024-3029 | HIGH | 8 | 0.7% | Apr 16, 2024 | In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to ... |
| CVE-2024-3028 | HIGH | 7.2 | 0.8% | Apr 16, 2024 | mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary f... |
| CVE-2024-1961 | HIGH | 8.8 | 1.0% | Apr 16, 2024 | vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its... |
| CVE-2024-1738 | HIGH | 7.5 | 0.5% | Apr 16, 2024 | An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.... |
| CVE-2024-1646 | HIGH | 8.2 | 0.7% | Apr 16, 2024 | parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. Th... |
| CVE-2024-1626 | HIGH | 8.1 | 0.5% | Apr 16, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, withi... |
| CVE-2024-1594 | HIGH | 7.5 | 0.7% | Apr 16, 2024 | A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact... |
| CVE-2024-1593 | HIGH | 7.5 | 0.7% | Apr 16, 2024 | A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smu... |
| CVE-2024-1569 | HIGH | 7.5 | 0.8% | Apr 16, 2024 | parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now