2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3402MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to ina...
CVE-2024-3153MEDIUM6.5mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint...
CVE-2024-3102MEDIUM5.3A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username ...
CVE-2024-3099MEDIUM5.4A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploit...
CVE-2024-37364MEDIUM6.8Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attac...
CVE-2024-37154MEDIUM5.3Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not y...
CVE-2024-36735MEDIUM5.3OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.
CVE-2024-32873MEDIUM4.3Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly whe...
CVE-2024-2965MEDIUM4.7A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, ...
CVE-2024-2383MEDIUM6.1A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failu...
CVE-2024-2171MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within t...
CVE-2024-2035MEDIUM6.5An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1...
CVE-2024-23793MEDIUM6.3The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits au...
CVE-2024-22326MEDIUM6.3IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remo...
CVE-2024-5268MEDIUM6.5Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows n...
CVE-2024-5256MEDIUM4.3Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows ne...
CVE-2024-5127MEDIUM5.4In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free pla...
CVE-2024-3504MEDIUM6.5An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin c...
CVE-2024-37156MEDIUM6.1The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is ...
CVE-2024-37150MEDIUM6.5An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to t...
CVE-2024-36399MEDIUM6.3Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer...
CVE-2024-36106MEDIUM4.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enume...
CVE-2024-5489MEDIUM4.3The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missin...
CVE-2024-5673MEDIUM6.1Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the ...
CVE-2024-5658MEDIUM6.5The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now