2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31986HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1...
CVE-2024-26362HIGH8.8HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to r...
CVE-2024-31984HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10...
CVE-2024-31983HIGH8.8XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit ri...
CVE-2024-31981HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc...
CVE-2024-31465HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9...
CVE-2024-31430HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professiona...
CVE-2024-29269HIGH8.8An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the ...
CVE-2024-23077HIGH7.5JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.jav...
CVE-2024-3569HIGH7.5A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is runn...
CVE-2024-3385HIGH7.5A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based f...
CVE-2024-3384HIGH7.5A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receivin...
CVE-2024-3382HIGH7.5A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets t...
CVE-2024-3283HIGH7.2A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin role...
CVE-2024-3101HIGH7.2In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by dea...
CVE-2024-31356HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us...
CVE-2024-31355HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slidesho...
CVE-2024-31343HIGH7.5Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue aff...
CVE-2024-31299HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scrip...
CVE-2024-2217HIGH7.5gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` f...
CVE-2024-2196HIGH8.8aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting ...
CVE-2024-1902HIGH7.5lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name withou...
CVE-2024-1728HIGH7.5gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied inpu...
CVE-2024-31873HIGH7.5IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inb...
CVE-2024-31872HIGH8.1IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now