2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3098 | CRITICAL | 9.8 | 1.0% | Apr 10, 2024 | A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eva... |
| CVE-2024-3025 | CRITICAL | 9.9 | 1.0% | Apr 10, 2024 | mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input... |
| CVE-2024-31356 | HIGH | 7.6 | 0.5% | Apr 10, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us... |
| CVE-2024-31355 | HIGH | 8.5 | 0.5% | Apr 10, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slidesho... |
| CVE-2024-31343 | HIGH | 7.5 | 0.6% | Apr 10, 2024 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue aff... |
| CVE-2024-31342 | MEDIUM | 6.5 | 0.5% | Apr 10, 2024 | Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Ex... |
| CVE-2024-31299 | HIGH | 7.1 | 0.3% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scrip... |
| CVE-2024-2952 | CRITICAL | 9.8 | 1.3% | Apr 10, 2024 | BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerabilit... |
| CVE-2024-2221 | CRITICAL | 9.8 | 1.8% | Apr 10, 2024 | qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTIO... |
| CVE-2024-2217 | HIGH | 7.5 | 0.8% | Apr 10, 2024 | gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` f... |
| CVE-2024-2196 | HIGH | 8.8 | 0.5% | Apr 10, 2024 | aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting ... |
| CVE-2024-2195 | CRITICAL | 9.8 | 1.8% | Apr 10, 2024 | A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the... |
| CVE-2024-2029 | CRITICAL | 9.8 | 2.9% | Apr 10, 2024 | A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioTo... |
| CVE-2024-1902 | HIGH | 7.5 | 0.4% | Apr 10, 2024 | lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name withou... |
| CVE-2024-1741 | CRITICAL | 9.1 | 0.6% | Apr 10, 2024 | lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify... |
| CVE-2024-1740 | CRITICAL | 9.1 | 0.6% | Apr 10, 2024 | In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, crea... |
| CVE-2024-1728 | HIGH | 7.5 | 85.4% | Apr 10, 2024 | gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied inpu... |
| CVE-2024-1643 | CRITICAL | 9.1 | 0.7% | Apr 10, 2024 | By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read a... |
| CVE-2024-1625 | MEDIUM | 6.5 | 0.4% | Apr 10, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allow... |
| CVE-2024-1602 | MEDIUM | 6.1 | 0.7% | Apr 10, 2024 | parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The ... |
| CVE-2024-1600 | CRITICAL | 9.3 | 31.1% | Apr 10, 2024 | A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/pe... |
| CVE-2024-1599 | — | — | — | Apr 10, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-1520 | CRITICAL | 9.8 | 48.2% | Apr 10, 2024 | An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui applicatio... |
| CVE-2024-1511 | CRITICAL | 9.8 | 1.0% | Apr 10, 2024 | The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of us... |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.9% | Apr 10, 2024 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now