2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3573CRITICAL9.3mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass ...
CVE-2024-3572HIGH7.5The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for...
CVE-2024-3571HIGH8.8langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted director...
CVE-2024-3271CRITICAL9.8A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func...
CVE-2024-3029HIGH8In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to ...
CVE-2024-3028HIGH7.2mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary f...
CVE-2024-30567MEDIUM6.3An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via ...
CVE-2024-2912CRITICAL10An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi...
CVE-2024-2260MEDIUM4.2A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication...
CVE-2024-2083CRITICAL9.9A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo...
CVE-2024-1961HIGH8.8vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its...
CVE-2024-1739CRITICAL9.1lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu...
CVE-2024-1738HIGH7.5An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations....
CVE-2024-1666MEDIUM5.3In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerabili...
CVE-2024-1665Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-1646HIGH8.2parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. Th...
CVE-2024-1626HIGH8.1An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, withi...
CVE-2024-1601CRITICAL9.8An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al...
CVE-2024-1594HIGH7.5A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact...
CVE-2024-1593HIGH7.5A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smu...
CVE-2024-1569HIGH7.5parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attack...
CVE-2024-1561HIGH7.5An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of...
CVE-2024-1560HIGH8.1A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functio...
CVE-2024-1558HIGH7.5A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflo...
CVE-2024-1483HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now