2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25566MEDIUM6.1An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect UR...
CVE-2024-10452LOW2.7Organization admins can delete pending invites created in an organization they are not part of.
CVE-2024-50334MEDIUM5.3Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /a...
CVE-2024-49769HIGH7.5Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before ...
CVE-2024-49768MEDIUM4.8Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly...
CVE-2024-48921LOW2.7Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can b...
CVE-2024-9505MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-51076MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ...
CVE-2024-51075MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Bo...
CVE-2024-49634MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Mem...
CVE-2024-49632MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D...
CVE-2024-47640MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp ...
CVE-2024-10226MEDIUM5.4The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcod...
CVE-2024-8309CRITICAL9.8A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through...
CVE-2024-8143MEDIUM4.3In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authen...
CVE-2024-7962HIGH7.5An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validatio...
CVE-2024-7807HIGH7.5A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi...
CVE-2024-7783HIGH7.5mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,...
CVE-2024-7774CRITICAL9.1A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulner...
CVE-2024-7475CRITICAL9.1An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configu...
CVE-2024-7474HIGH8.1In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o...
CVE-2024-7473MEDIUM6.5An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions ...
CVE-2024-7472MEDIUM6.5lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-ve...
CVE-2024-7042CRITICAL9.8A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this cl...
CVE-2024-7010MEDIUM5.9mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now