2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6868CRITICAL9.8mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. ...
CVE-2024-6674HIGH7.1A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information suc...
CVE-2024-6673MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` fi...
CVE-2024-6581CRITICAL9A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploadin...
CVE-2024-5982CRITICAL9.8A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from...
CVE-2024-5823CRITICAL9.1A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an a...
CVE-2024-51181MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code ...
CVE-2024-51180MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder P...
CVE-2024-49645MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affi...
CVE-2024-49643MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fifthsegment White...
CVE-2024-49641MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tidaweb Tida URL S...
CVE-2024-49640MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmaderCode Lab ACL...
CVE-2024-49639MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Mon...
CVE-2024-49638MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ventureharbour Ris...
CVE-2024-49637MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foxskav Bet WC 201...
CVE-2024-49636MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woracal Agile Vide...
CVE-2024-49635MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manjurul.cis Banne...
CVE-2024-41156LOW2.7Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide po...
CVE-2024-41153HIGH7.2Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a...
CVE-2024-10474MEDIUM6.5Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in link...
CVE-2024-10468MEDIUM5.3Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. ...
CVE-2024-10467HIGH8.8Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ...
CVE-2024-10466HIGH7.5By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ...
CVE-2024-10465MEDIUM6.5A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox...
CVE-2024-10464MEDIUM6.5Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the brows...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now