2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44081 | CRITICAL | 9.8 | 0.7% | Oct 29, 2024 | In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in ... |
| CVE-2024-48206 | CRITICAL | 9.8 | 0.8% | Oct 29, 2024 | A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code. |
| CVE-2024-48063 | CRITICAL | 9.8 | 1.6% | Oct 29, 2024 | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is... |
| CVE-2024-9989 | CRITICAL | 9.8 | 7.2% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d... |
| CVE-2024-9988 | CRITICAL | 9.8 | 1.1% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d... |
| CVE-2024-50459 | CRITICAL | 9.8 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured ... |
| CVE-2024-8923 | CRITICAL | 10 | 1.1% | Oct 29, 2024 | ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability c... |
| CVE-2024-8309 | CRITICAL | 9.8 | 13.8% | Oct 29, 2024 | A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through... |
| CVE-2024-7774 | CRITICAL | 9.1 | 0.5% | Oct 29, 2024 | A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulner... |
| CVE-2024-7475 | CRITICAL | 9.1 | 0.6% | Oct 29, 2024 | An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configu... |
| CVE-2024-7042 | CRITICAL | 9.8 | 0.3% | Oct 29, 2024 | A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this cl... |
| CVE-2024-6868 | CRITICAL | 9.8 | 1.5% | Oct 29, 2024 | mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. ... |
| CVE-2024-6581 | CRITICAL | 9 | 0.6% | Oct 29, 2024 | A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploadin... |
| CVE-2024-5982 | CRITICAL | 9.8 | 27.2% | Oct 29, 2024 | A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from... |
| CVE-2024-5823 | CRITICAL | 9.1 | 0.5% | Oct 29, 2024 | A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an a... |
| CVE-2024-50550 | CRITICAL | 9.8 | 0.9% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege ... |
| CVE-2024-50490 | CRITICAL | 9.8 | 1.0% | Oct 29, 2024 | Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained... |
| CVE-2024-50485 | CRITICAL | 9.8 | 1.0% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issu... |
| CVE-2024-50476 | CRITICAL | 9.8 | 1.2% | Oct 29, 2024 | Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege ... |
| CVE-2024-50475 | CRITICAL | 9.8 | 1.2% | Oct 29, 2024 | Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affect... |
| CVE-2024-50473 | CRITICAL | 10 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em... |
| CVE-2024-50427 | CRITICAL | 9.9 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects Surv... |
| CVE-2024-50420 | CRITICAL | 10 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Sh... |
| CVE-2024-50494 | CRITICAL | 10 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-suda... |
| CVE-2024-50493 | CRITICAL | 10 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now