2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-8537CRITICAL9.1A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerabilit...
CVE-2024-8502CRITICAL9.8A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (...
CVE-2024-8487CRITICAL9.8A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configurat...
CVE-2024-8196CRITICAL9.8In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit...
CVE-2024-8156CRITICAL9.8A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untru...
CVE-2024-8019CRITICAL9.1In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows ...
CVE-2024-8017CRITICAL9An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the...
CVE-2024-7957CRITICAL9.1An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest versi...
CVE-2024-7776CRITICAL9.1A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows...
CVE-2024-7760CRITICAL9.6aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulne...
CVE-2024-7053CRITICAL9A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session...
CVE-2024-6829CRITICAL9.1A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extr...
CVE-2024-5752CRITICAL9.1A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the af...
CVE-2024-4990CRITICAL9.1In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does ...
CVE-2024-12909CRITICAL9.8A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for ...
CVE-2024-12450CRITICAL9.8In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. ...
CVE-2024-12433CRITICAL9.8A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses ...
CVE-2024-12044CRITICAL9.8A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the u...
CVE-2024-12029CRITICAL9.8A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/i...
CVE-2024-11958CRITICAL9.8A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specif...
CVE-2024-11045CRITICAL9.6A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an ...
CVE-2024-11042CRITICAL9.1In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion....
CVE-2024-11041CRITICAL9.8vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses ...
CVE-2024-10902CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Uplo...
CVE-2024-10901CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now