2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31986 | HIGH | 8.8 | 0.5% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1... |
| CVE-2024-26362 | HIGH | 8.8 | 0.6% | Apr 10, 2024 | HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to r... |
| CVE-2024-31984 | HIGH | 8.8 | 83.0% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10... |
| CVE-2024-31983 | HIGH | 8.8 | 1.4% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit ri... |
| CVE-2024-31981 | HIGH | 8.8 | 1.4% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc... |
| CVE-2024-31465 | HIGH | 8.8 | 75.6% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9... |
| CVE-2024-31430 | HIGH | 8.8 | 0.2% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professiona... |
| CVE-2024-29269 | HIGH | 8.8 | 5.9% | Apr 10, 2024 | An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the ... |
| CVE-2024-23077 | HIGH | 7.5 | 0.6% | Apr 10, 2024 | JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.jav... |
| CVE-2024-3569 | HIGH | 7.5 | 0.8% | Apr 10, 2024 | A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is runn... |
| CVE-2024-3385 | HIGH | 7.5 | 0.9% | Apr 10, 2024 | A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based f... |
| CVE-2024-3384 | HIGH | 7.5 | 0.9% | Apr 10, 2024 | A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receivin... |
| CVE-2024-3382 | HIGH | 7.5 | 0.9% | Apr 10, 2024 | A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets t... |
| CVE-2024-3283 | HIGH | 7.2 | 0.9% | Apr 10, 2024 | A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin role... |
| CVE-2024-3101 | HIGH | 7.2 | 0.8% | Apr 10, 2024 | In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by dea... |
| CVE-2024-31356 | HIGH | 7.6 | 0.5% | Apr 10, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us... |
| CVE-2024-31355 | HIGH | 8.5 | 0.5% | Apr 10, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slidesho... |
| CVE-2024-31343 | HIGH | 7.5 | 0.6% | Apr 10, 2024 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue aff... |
| CVE-2024-31299 | HIGH | 7.1 | 0.3% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scrip... |
| CVE-2024-2217 | HIGH | 7.5 | 0.8% | Apr 10, 2024 | gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` f... |
| CVE-2024-2196 | HIGH | 8.8 | 0.5% | Apr 10, 2024 | aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting ... |
| CVE-2024-1902 | HIGH | 7.5 | 0.4% | Apr 10, 2024 | lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name withou... |
| CVE-2024-1728 | HIGH | 7.5 | 85.4% | Apr 10, 2024 | gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied inpu... |
| CVE-2024-31873 | HIGH | 7.5 | 1.2% | Apr 10, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inb... |
| CVE-2024-31872 | HIGH | 8.1 | 0.6% | Apr 10, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now