2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48591 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded tha... |
| CVE-2024-48590 | CRITICAL | 9.8 | 0.7% | Mar 20, 2025 | Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an... |
| CVE-2024-13923 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all... |
| CVE-2024-13922 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins... |
| CVE-2024-13921 | HIGH | 7.2 | 0.6% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio... |
| CVE-2024-13920 | MEDIUM | 4.9 | 0.7% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version... |
| CVE-2024-13558 | MEDIUM | 5.3 | 0.3% | Mar 20, 2025 | The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi... |
| CVE-2024-9920 | HIGH | 8.8 | 1.2% | Mar 20, 2025 | In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ... |
| CVE-2024-9919 | HIGH | 8.4 | 0.3% | Mar 20, 2025 | A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth... |
| CVE-2024-9901 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-48057. N... |
| CVE-2024-9900 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vuln... |
| CVE-2024-9880 | — | — | — | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-9847 | HIGH | 8 | 0.3% | Mar 20, 2025 | FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable... |
| CVE-2024-9840 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. N... |
| CVE-2024-9701 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vu... |
| CVE-2024-9699 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to... |
| CVE-2024-9617 | MEDIUM | 6.5 | 1.6% | Mar 20, 2025 | An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verif... |
| CVE-2024-9612 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search p... |
| CVE-2024-9606 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerabi... |
| CVE-2024-9597 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attac... |
| CVE-2024-9447 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisat... |
| CVE-2024-9439 | HIGH | 8.8 | 1.1% | Mar 20, 2025 | SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers ... |
| CVE-2024-9437 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in... |
| CVE-2024-9431 | HIGH | 8.8 | 0.6% | Mar 20, 2025 | In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After loggin... |
| CVE-2024-9418 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now