2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25566 | MEDIUM | 6.1 | 0.2% | Oct 29, 2024 | An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect UR... |
| CVE-2024-10452 | LOW | 2.7 | 0.5% | Oct 29, 2024 | Organization admins can delete pending invites created in an organization they are not part of. |
| CVE-2024-50334 | MEDIUM | 5.3 | 1.0% | Oct 29, 2024 | Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /a... |
| CVE-2024-49769 | HIGH | 7.5 | 1.4% | Oct 29, 2024 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before ... |
| CVE-2024-49768 | MEDIUM | 4.8 | 0.5% | Oct 29, 2024 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly... |
| CVE-2024-48921 | LOW | 2.7 | 0.6% | Oct 29, 2024 | Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can b... |
| CVE-2024-9505 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-51076 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ... |
| CVE-2024-51075 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Bo... |
| CVE-2024-49634 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Mem... |
| CVE-2024-49632 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D... |
| CVE-2024-47640 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp ... |
| CVE-2024-10226 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcod... |
| CVE-2024-8309 | CRITICAL | 9.8 | 13.8% | Oct 29, 2024 | A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through... |
| CVE-2024-8143 | MEDIUM | 4.3 | 0.5% | Oct 29, 2024 | In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authen... |
| CVE-2024-7962 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validatio... |
| CVE-2024-7807 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi... |
| CVE-2024-7783 | HIGH | 7.5 | 0.3% | Oct 29, 2024 | mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,... |
| CVE-2024-7774 | CRITICAL | 9.1 | 0.5% | Oct 29, 2024 | A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulner... |
| CVE-2024-7475 | CRITICAL | 9.1 | 0.6% | Oct 29, 2024 | An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configu... |
| CVE-2024-7474 | HIGH | 8.1 | 0.5% | Oct 29, 2024 | In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o... |
| CVE-2024-7473 | MEDIUM | 6.5 | 0.4% | Oct 29, 2024 | An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions ... |
| CVE-2024-7472 | MEDIUM | 6.5 | 0.4% | Oct 29, 2024 | lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-ve... |
| CVE-2024-7042 | CRITICAL | 9.8 | 0.3% | Oct 29, 2024 | A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this cl... |
| CVE-2024-7010 | MEDIUM | 5.9 | 0.5% | Oct 29, 2024 | mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now