2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3402 | MEDIUM | 5.4 | 0.5% | Jun 6, 2024 | A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to ina... |
| CVE-2024-3153 | MEDIUM | 6.5 | 0.7% | Jun 6, 2024 | mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint... |
| CVE-2024-3102 | MEDIUM | 5.3 | 0.5% | Jun 6, 2024 | A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username ... |
| CVE-2024-3099 | MEDIUM | 5.4 | 0.4% | Jun 6, 2024 | A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploit... |
| CVE-2024-37364 | MEDIUM | 6.8 | 0.3% | Jun 6, 2024 | Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attac... |
| CVE-2024-37154 | MEDIUM | 5.3 | 0.4% | Jun 6, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not y... |
| CVE-2024-36735 | MEDIUM | 5.3 | 0.4% | Jun 6, 2024 | OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating. |
| CVE-2024-32873 | MEDIUM | 4.3 | 0.4% | Jun 6, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly whe... |
| CVE-2024-2965 | MEDIUM | 4.7 | 0.3% | Jun 6, 2024 | A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, ... |
| CVE-2024-2383 | MEDIUM | 6.1 | 0.4% | Jun 6, 2024 | A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failu... |
| CVE-2024-2171 | MEDIUM | 4.8 | 0.4% | Jun 6, 2024 | A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within t... |
| CVE-2024-2035 | MEDIUM | 6.5 | 0.6% | Jun 6, 2024 | An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1... |
| CVE-2024-23793 | MEDIUM | 6.3 | 0.8% | Jun 6, 2024 | The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits au... |
| CVE-2024-22326 | MEDIUM | 6.3 | 0.4% | Jun 6, 2024 | IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remo... |
| CVE-2024-5268 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows n... |
| CVE-2024-5256 | MEDIUM | 4.3 | 0.4% | Jun 6, 2024 | Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows ne... |
| CVE-2024-5127 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free pla... |
| CVE-2024-3504 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin c... |
| CVE-2024-37156 | MEDIUM | 6.1 | 0.3% | Jun 6, 2024 | The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is ... |
| CVE-2024-37150 | MEDIUM | 6.5 | 0.4% | Jun 6, 2024 | An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to t... |
| CVE-2024-36399 | MEDIUM | 6.3 | 0.4% | Jun 6, 2024 | Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer... |
| CVE-2024-36106 | MEDIUM | 4.3 | 0.4% | Jun 6, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enume... |
| CVE-2024-5489 | MEDIUM | 4.3 | 0.5% | Jun 6, 2024 | The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missin... |
| CVE-2024-5673 | MEDIUM | 6.1 | 0.3% | Jun 6, 2024 | Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the ... |
| CVE-2024-5658 | MEDIUM | 6.5 | 0.6% | Jun 6, 2024 | The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now