2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38988 | CRITICAL | 9.8 | 0.7% | Mar 28, 2025 | alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/inde... |
| CVE-2024-38985 | CRITICAL | 9.8 | 0.7% | Mar 28, 2025 | janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() met... |
| CVE-2024-24292 | CRITICAL | 9.8 | 0.7% | Mar 28, 2025 | A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function... |
| CVE-2024-49601 | CRITICAL | 9.8 | 1.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-55964 | CRITICAL | 9.8 | 6.3% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea... |
| CVE-2024-47516 | CRITICAL | 9.8 | 0.8% | Mar 26, 2025 | A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re... |
| CVE-2024-55030 | CRITICAL | 9.8 | 1.7% | Mar 25, 2025 | A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar... |
| CVE-2024-55028 | CRITICAL | 9.8 | 0.7% | Mar 25, 2025 | A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via... |
| CVE-2024-48818 | CRITICAL | 9.8 | 0.8% | Mar 25, 2025 | An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code. |
| CVE-2024-42533 | CRITICAL | 9.8 | 0.6% | Mar 25, 2025 | SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker... |
| CVE-2024-45480 | CRITICAL | 9.2 | 0.4% | Mar 25, 2025 | An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APR... |
| CVE-2024-53351 | CRITICAL | 9.8 | 0.5% | Mar 21, 2025 | Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio... |
| CVE-2024-48590 | CRITICAL | 9.8 | 0.7% | Mar 20, 2025 | Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an... |
| CVE-2024-9701 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vu... |
| CVE-2024-9309 | CRITICAL | 9.3 | 0.5% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro... |
| CVE-2024-9095 | CRITICAL | 9.8 | 0.7% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to... |
| CVE-2024-9070 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ... |
| CVE-2024-9053 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ... |
| CVE-2024-8958 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools action... |
| CVE-2024-8954 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authenticatio... |
| CVE-2024-8953 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform ma... |
| CVE-2024-8898 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V1... |
| CVE-2024-8769 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file d... |
| CVE-2024-8581 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any ... |
| CVE-2024-8551 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope vers... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now