2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6868 | CRITICAL | 9.8 | 1.5% | Oct 29, 2024 | mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. ... |
| CVE-2024-6674 | HIGH | 7.1 | 0.2% | Oct 29, 2024 | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information suc... |
| CVE-2024-6673 | MEDIUM | 6.5 | 0.2% | Oct 29, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` fi... |
| CVE-2024-6581 | CRITICAL | 9 | 0.6% | Oct 29, 2024 | A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploadin... |
| CVE-2024-5982 | CRITICAL | 9.8 | 27.2% | Oct 29, 2024 | A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from... |
| CVE-2024-5823 | CRITICAL | 9.1 | 0.5% | Oct 29, 2024 | A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an a... |
| CVE-2024-51181 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code ... |
| CVE-2024-51180 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder P... |
| CVE-2024-49645 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affi... |
| CVE-2024-49643 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fifthsegment White... |
| CVE-2024-49641 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tidaweb Tida URL S... |
| CVE-2024-49640 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmaderCode Lab ACL... |
| CVE-2024-49639 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Mon... |
| CVE-2024-49638 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ventureharbour Ris... |
| CVE-2024-49637 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foxskav Bet WC 201... |
| CVE-2024-49636 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woracal Agile Vide... |
| CVE-2024-49635 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manjurul.cis Banne... |
| CVE-2024-41156 | LOW | 2.7 | 0.4% | Oct 29, 2024 | Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide po... |
| CVE-2024-41153 | HIGH | 7.2 | 1.6% | Oct 29, 2024 | Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a... |
| CVE-2024-10474 | MEDIUM | 6.5 | 0.3% | Oct 29, 2024 | Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in link... |
| CVE-2024-10468 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. ... |
| CVE-2024-10467 | HIGH | 8.8 | 0.6% | Oct 29, 2024 | Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ... |
| CVE-2024-10466 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ... |
| CVE-2024-10465 | MEDIUM | 6.5 | 0.5% | Oct 29, 2024 | A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox... |
| CVE-2024-10464 | MEDIUM | 6.5 | 0.6% | Oct 29, 2024 | Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the brows... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now