2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-38988CRITICAL9.8alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/inde...
CVE-2024-38985CRITICAL9.8janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() met...
CVE-2024-24292CRITICAL9.8A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function...
CVE-2024-49601CRITICAL9.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-55964CRITICAL9.8An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea...
CVE-2024-47516CRITICAL9.8A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re...
CVE-2024-55030CRITICAL9.8A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar...
CVE-2024-55028CRITICAL9.8A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via...
CVE-2024-48818CRITICAL9.8An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.
CVE-2024-42533CRITICAL9.8SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker...
CVE-2024-45480CRITICAL9.2An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APR...
CVE-2024-53351CRITICAL9.8Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio...
CVE-2024-48590CRITICAL9.8Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an...
CVE-2024-9701CRITICAL9.8A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vu...
CVE-2024-9309CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro...
CVE-2024-9095CRITICAL9.8In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to...
CVE-2024-9070CRITICAL9.8A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ...
CVE-2024-9053CRITICAL9.8vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ...
CVE-2024-8958CRITICAL9.8In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools action...
CVE-2024-8954CRITICAL9.8In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authenticatio...
CVE-2024-8953CRITICAL9.8In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform ma...
CVE-2024-8898CRITICAL9.8A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V1...
CVE-2024-8769CRITICAL9.1A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file d...
CVE-2024-8581CRITICAL9.1A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any ...
CVE-2024-8551CRITICAL9.1A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope vers...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now