2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3099MEDIUM5.4A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploit...
CVE-2024-3095HIGH7.7A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langch...
CVE-2024-37364MEDIUM6.8Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attac...
CVE-2024-37154MEDIUM5.3Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not y...
CVE-2024-37153HIGH7.5Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using ...
CVE-2024-36740HIGH7.5An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative num...
CVE-2024-36735MEDIUM5.3OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.
CVE-2024-36734HIGH7.5Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti...
CVE-2024-36732HIGH7.5An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is proce...
CVE-2024-36730HIGH7.5Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti...
CVE-2024-32873MEDIUM4.3Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly whe...
CVE-2024-30373HIGH7.8Kofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-2965MEDIUM4.7A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, ...
CVE-2024-2928HIGH7.5A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix...
CVE-2024-2624CRITICAL9.8A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically w...
CVE-2024-2548HIGH7.5A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lol...
CVE-2024-2383MEDIUM6.1A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failu...
CVE-2024-2362CRITICAL9.1A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper ...
CVE-2024-2360CRITICAL9.8parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient...
CVE-2024-2359CRITICAL9.8A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and exe...
CVE-2024-2288HIGH8.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms appli...
CVE-2024-2213LOW3.3An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms...
CVE-2024-2171MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within t...
CVE-2024-2035MEDIUM6.5An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1...
CVE-2024-2032LOW3.1A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creati...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now