2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48591MEDIUM6.1Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded tha...
CVE-2024-48590CRITICAL9.8Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an...
CVE-2024-13923MEDIUM6.5The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
CVE-2024-13922MEDIUM6.5The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins...
CVE-2024-13921HIGH7.2The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio...
CVE-2024-13920MEDIUM4.9The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version...
CVE-2024-13558MEDIUM5.3The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi...
CVE-2024-9920HIGH8.8In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ...
CVE-2024-9919HIGH8.4A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth...
CVE-2024-9901Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-48057. N...
CVE-2024-9900MEDIUM6.1mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vuln...
CVE-2024-9880Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-9847HIGH8FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable...
CVE-2024-9840Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. N...
CVE-2024-9701CRITICAL9.8A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vu...
CVE-2024-9699MEDIUM5.4A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to...
CVE-2024-9617MEDIUM6.5An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verif...
CVE-2024-9612MEDIUM6.5In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search p...
CVE-2024-9606HIGH7.5In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerabi...
CVE-2024-9597HIGH7.1A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attac...
CVE-2024-9447MEDIUM6.5An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisat...
CVE-2024-9439HIGH8.8SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers ...
CVE-2024-9437HIGH7.5SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in...
CVE-2024-9431HIGH8.8In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After loggin...
CVE-2024-9418MEDIUM6.5In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now