2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-32086HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affect...
CVE-2024-3874HIGH8.8A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the func...
CVE-2024-3865HIGH8.1Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-3864HIGH8.1Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c...
CVE-2024-3858HIGH7.5It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F...
CVE-2024-3857HIGH7.8The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garba...
CVE-2024-3856HIGH8.8A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulne...
CVE-2024-3854HIGH8.8In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This ...
CVE-2024-3853HIGH7.5A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection st...
CVE-2024-3852HIGH7.5GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects...
CVE-2024-3067HIGH7.2The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve...
CVE-2024-32631HIGH8Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
CVE-2024-22262HIGH8.1Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf...
CVE-2024-3574HIGH7.5In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server auth...
CVE-2024-3572HIGH7.5The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for...
CVE-2024-3571HIGH8.8langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted director...
CVE-2024-3029HIGH8In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to ...
CVE-2024-3028HIGH7.2mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary f...
CVE-2024-1961HIGH8.8vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its...
CVE-2024-1738HIGH7.5An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations....
CVE-2024-1646HIGH8.2parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. Th...
CVE-2024-1626HIGH8.1An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, withi...
CVE-2024-1594HIGH7.5A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact...
CVE-2024-1593HIGH7.5A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smu...
CVE-2024-1569HIGH7.5parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now