2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10110HIGH7.5In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of t...
CVE-2024-10109HIGH8.3A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access...
CVE-2024-10096Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-10051HIGH7.5Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in ...
CVE-2024-10047MEDIUM5.3parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can l...
CVE-2024-10019MEDIUM6.7A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a...
CVE-2024-0640MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerabilit...
CVE-2024-0245MEDIUM5.5A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln...
CVE-2024-54016MEDIUM4.3Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue...
CVE-2024-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incu...
CVE-2024-12016CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM ...
CVE-2024-13881HIGH7.1The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13880HIGH7.1The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13878HIGH7.1The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13877HIGH7.1The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before ou...
CVE-2024-13876HIGH7.1The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13875HIGH7.1The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-55009MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and...
CVE-2024-7631MEDIUM4.3A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/re...
CVE-2024-57061CRITICAL9.8An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via ...
CVE-2024-51459HIGH7.8IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handl...
CVE-2024-25132MEDIUM4.3A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshi...
CVE-2024-53970MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-53969MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-53968MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now