2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3098CRITICAL9.8A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eva...
CVE-2024-3025CRITICAL9.9mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input...
CVE-2024-31356HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us...
CVE-2024-31355HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slidesho...
CVE-2024-31343HIGH7.5Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue aff...
CVE-2024-31342MEDIUM6.5Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Ex...
CVE-2024-31299HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scrip...
CVE-2024-2952CRITICAL9.8BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerabilit...
CVE-2024-2221CRITICAL9.8qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTIO...
CVE-2024-2217HIGH7.5gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` f...
CVE-2024-2196HIGH8.8aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting ...
CVE-2024-2195CRITICAL9.8A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the...
CVE-2024-2029CRITICAL9.8A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioTo...
CVE-2024-1902HIGH7.5lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name withou...
CVE-2024-1741CRITICAL9.1lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify...
CVE-2024-1740CRITICAL9.1In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, crea...
CVE-2024-1728HIGH7.5gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied inpu...
CVE-2024-1643CRITICAL9.1By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read a...
CVE-2024-1625MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allow...
CVE-2024-1602MEDIUM6.1parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The ...
CVE-2024-1600CRITICAL9.3A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/pe...
CVE-2024-1599Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-1520CRITICAL9.8An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui applicatio...
CVE-2024-1511CRITICAL9.8The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of us...
CVE-2024-3566CRITICAL9.8A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now