2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8537 | CRITICAL | 9.1 | 1.0% | Mar 20, 2025 | A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerabilit... |
| CVE-2024-8502 | CRITICAL | 9.8 | 1.6% | Mar 20, 2025 | A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (... |
| CVE-2024-8487 | CRITICAL | 9.8 | 0.3% | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configurat... |
| CVE-2024-8196 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit... |
| CVE-2024-8156 | CRITICAL | 9.8 | 1.7% | Mar 20, 2025 | A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untru... |
| CVE-2024-8019 | CRITICAL | 9.1 | 1.0% | Mar 20, 2025 | In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows ... |
| CVE-2024-8017 | CRITICAL | 9 | 0.6% | Mar 20, 2025 | An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the... |
| CVE-2024-7957 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest versi... |
| CVE-2024-7776 | CRITICAL | 9.1 | 1.4% | Mar 20, 2025 | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows... |
| CVE-2024-7760 | CRITICAL | 9.6 | 0.5% | Mar 20, 2025 | aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulne... |
| CVE-2024-7053 | CRITICAL | 9 | 0.7% | Mar 20, 2025 | A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session... |
| CVE-2024-6829 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extr... |
| CVE-2024-5752 | CRITICAL | 9.1 | 1.4% | Mar 20, 2025 | A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the af... |
| CVE-2024-4990 | CRITICAL | 9.1 | 79.4% | Mar 20, 2025 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does ... |
| CVE-2024-12909 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for ... |
| CVE-2024-12450 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. ... |
| CVE-2024-12433 | CRITICAL | 9.8 | 1.5% | Mar 20, 2025 | A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses ... |
| CVE-2024-12044 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the u... |
| CVE-2024-12029 | CRITICAL | 9.8 | 5.3% | Mar 20, 2025 | A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/i... |
| CVE-2024-11958 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specif... |
| CVE-2024-11045 | CRITICAL | 9.6 | 0.4% | Mar 20, 2025 | A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an ... |
| CVE-2024-11042 | CRITICAL | 9.1 | 1.3% | Mar 20, 2025 | In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion.... |
| CVE-2024-11041 | CRITICAL | 9.8 | 1.4% | Mar 20, 2025 | vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses ... |
| CVE-2024-10902 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Uplo... |
| CVE-2024-10901 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now