2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40598MEDIUM4.3An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed informati...
CVE-2024-40597HIGH7.5An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information fo...
CVE-2024-40596MEDIUM4.3An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can exp...
CVE-2024-6095MEDIUM5.8A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (...
CVE-2024-37554MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Ultra...
CVE-2024-37553MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant T...
CVE-2024-37547MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons...
CVE-2024-37546MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 I...
CVE-2024-37542MEDIUM6.3Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Im...
CVE-2024-37541MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StaxWP Elementor A...
CVE-2024-37539MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Delower WP ...
CVE-2024-39486HIGH7In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <maarten.la...
CVE-2024-37260CRITICAL9.3Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.
CVE-2024-37234LOW3.5URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad...
CVE-2024-37208MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Robert Macchi WP Scraper.This issue affects WP Scraper: from n/a thr...
CVE-2024-5616MEDIUM4.3A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which al...
CVE-2024-40594LOW2.3The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l...
CVE-2024-39182HIGH7.5An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root u...
CVE-2024-33862HIGH7.5A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow...
CVE-2024-5753HIGH7.5vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. T...
CVE-2024-39696HIGH8.1Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can creat...
CVE-2024-39691MEDIUM4.3matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2...
CVE-2024-39689HIGH7.5Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify...
CVE-2024-39023HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=ad...
CVE-2024-39022HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mud...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now