2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1561 | HIGH | 7.5 | 9.2% | Apr 16, 2024 | An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of... |
| CVE-2024-1560 | HIGH | 8.1 | 0.9% | Apr 16, 2024 | A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functio... |
| CVE-2024-1558 | HIGH | 7.5 | 0.9% | Apr 16, 2024 | A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflo... |
| CVE-2024-1483 | HIGH | 7.5 | 2.7% | Apr 16, 2024 | A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on th... |
| CVE-2024-1456 | HIGH | 7.1 | 0.2% | Apr 16, 2024 | An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http... |
| CVE-2024-1135 | HIGH | 7.5 | 3.0% | Apr 16, 2024 | Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. ... |
| CVE-2024-0549 | HIGH | 8.1 | 0.8% | Apr 16, 2024 | mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a def... |
| CVE-2024-3493 | HIGH | 7.5 | 0.6% | Apr 15, 2024 | A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send lar... |
| CVE-2024-30656 | HIGH | 7.5 | 0.4% | Apr 15, 2024 | An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of S... |
| CVE-2024-2424 | HIGH | 7.5 | 2.6% | Apr 15, 2024 | An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to r... |
| CVE-2024-28558 | HIGH | 8.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute a... |
| CVE-2024-24485 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information... |
| CVE-2024-2659 | HIGH | 7.2 | 1.1% | Apr 15, 2024 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat... |
| CVE-2024-22014 | HIGH | 8.8 | 0.8% | Apr 15, 2024 | An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated p... |
| CVE-2024-3782 | HIGH | 8.8 | 0.3% | Apr 15, 2024 | Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated H... |
| CVE-2024-3780 | HIGH | 7.8 | 0.2% | Apr 15, 2024 | A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerabi... |
| CVE-2024-31382 | HIGH | 8.8 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a... |
| CVE-2024-31378 | HIGH | 8.8 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp F... |
| CVE-2024-31374 | HIGH | 8.8 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forger... |
| CVE-2024-30220 | HIGH | 8.8 | 1.0% | Apr 15, 2024 | Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated ... |
| CVE-2024-29219 | HIGH | 7.8 | 0.3% | Apr 15, 2024 | Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, an... |
| CVE-2024-29218 | HIGH | 8.8 | 0.8% | Apr 15, 2024 | Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and ... |
| CVE-2024-28099 | HIGH | 7.8 | 0.2% | Apr 15, 2024 | VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic ... |
| CVE-2024-23911 | HIGH | 7.5 | 0.6% | Apr 15, 2024 | Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in C... |
| CVE-2024-31429 | HIGH | 8.8 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now