2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-1561HIGH7.5An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of...
CVE-2024-1560HIGH8.1A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functio...
CVE-2024-1558HIGH7.5A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflo...
CVE-2024-1483HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on th...
CVE-2024-1456HIGH7.1An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http...
CVE-2024-1135HIGH7.5Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. ...
CVE-2024-0549HIGH8.1mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a def...
CVE-2024-3493HIGH7.5 A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send lar...
CVE-2024-30656HIGH7.5An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of S...
CVE-2024-2424HIGH7.5 An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to r...
CVE-2024-28558HIGH8.8SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute a...
CVE-2024-24485HIGH7.5An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information...
CVE-2024-2659HIGH7.2 A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat...
CVE-2024-22014HIGH8.8An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated p...
CVE-2024-3782HIGH8.8Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated H...
CVE-2024-3780HIGH7.8A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerabi...
CVE-2024-31382HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a...
CVE-2024-31378HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp F...
CVE-2024-31374HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forger...
CVE-2024-30220HIGH8.8Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated ...
CVE-2024-29219HIGH7.8Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, an...
CVE-2024-29218HIGH8.8Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and ...
CVE-2024-28099HIGH7.8VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic ...
CVE-2024-23911HIGH7.5Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in C...
CVE-2024-31429HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now