2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3573 | CRITICAL | 9.3 | 0.7% | Apr 16, 2024 | mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass ... |
| CVE-2024-3572 | HIGH | 7.5 | 0.8% | Apr 16, 2024 | The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for... |
| CVE-2024-3571 | HIGH | 8.8 | 1.9% | Apr 16, 2024 | langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted director... |
| CVE-2024-3271 | CRITICAL | 9.8 | 2.9% | Apr 16, 2024 | A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func... |
| CVE-2024-3029 | HIGH | 8 | 0.7% | Apr 16, 2024 | In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to ... |
| CVE-2024-3028 | HIGH | 7.2 | 0.8% | Apr 16, 2024 | mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary f... |
| CVE-2024-30567 | MEDIUM | 6.3 | 0.6% | Apr 16, 2024 | An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-2912 | CRITICAL | 10 | 1.5% | Apr 16, 2024 | An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi... |
| CVE-2024-2260 | MEDIUM | 4.2 | 0.4% | Apr 16, 2024 | A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication... |
| CVE-2024-2083 | CRITICAL | 9.9 | 39.1% | Apr 16, 2024 | A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo... |
| CVE-2024-1961 | HIGH | 8.8 | 1.0% | Apr 16, 2024 | vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its... |
| CVE-2024-1739 | CRITICAL | 9.1 | 0.6% | Apr 16, 2024 | lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu... |
| CVE-2024-1738 | HIGH | 7.5 | 0.5% | Apr 16, 2024 | An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.... |
| CVE-2024-1666 | MEDIUM | 5.3 | 0.5% | Apr 16, 2024 | In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerabili... |
| CVE-2024-1665 | — | — | — | Apr 16, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-1646 | HIGH | 8.2 | 0.7% | Apr 16, 2024 | parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. Th... |
| CVE-2024-1626 | HIGH | 8.1 | 0.5% | Apr 16, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, withi... |
| CVE-2024-1601 | CRITICAL | 9.8 | 40.4% | Apr 16, 2024 | An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al... |
| CVE-2024-1594 | HIGH | 7.5 | 0.7% | Apr 16, 2024 | A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact... |
| CVE-2024-1593 | HIGH | 7.5 | 0.7% | Apr 16, 2024 | A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smu... |
| CVE-2024-1569 | HIGH | 7.5 | 0.8% | Apr 16, 2024 | parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attack... |
| CVE-2024-1561 | HIGH | 7.5 | 9.2% | Apr 16, 2024 | An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of... |
| CVE-2024-1560 | HIGH | 8.1 | 0.9% | Apr 16, 2024 | A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functio... |
| CVE-2024-1558 | HIGH | 7.5 | 0.9% | Apr 16, 2024 | A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflo... |
| CVE-2024-1483 | HIGH | 7.5 | 2.7% | Apr 16, 2024 | A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now