2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-44081CRITICAL9.8In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in ...
CVE-2024-48206CRITICAL9.8A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.
CVE-2024-48063CRITICAL9.8In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is...
CVE-2024-9989CRITICAL9.8The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d...
CVE-2024-9988CRITICAL9.8The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d...
CVE-2024-50459CRITICAL9.8Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured ...
CVE-2024-8923CRITICAL10ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability c...
CVE-2024-8309CRITICAL9.8A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through...
CVE-2024-7774CRITICAL9.1A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulner...
CVE-2024-7475CRITICAL9.1An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configu...
CVE-2024-7042CRITICAL9.8A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this cl...
CVE-2024-6868CRITICAL9.8mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. ...
CVE-2024-6581CRITICAL9A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploadin...
CVE-2024-5982CRITICAL9.8A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from...
CVE-2024-5823CRITICAL9.1A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an a...
CVE-2024-50550CRITICAL9.8Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege ...
CVE-2024-50490CRITICAL9.8Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained...
CVE-2024-50485CRITICAL9.8Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issu...
CVE-2024-50476CRITICAL9.8Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege ...
CVE-2024-50475CRITICAL9.8Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affect...
CVE-2024-50473CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em...
CVE-2024-50427CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects Surv...
CVE-2024-50420CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Sh...
CVE-2024-50494CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-suda...
CVE-2024-50493CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now