2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9439HIGH8.8SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers ...
CVE-2024-9437HIGH7.5SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in...
CVE-2024-9431HIGH8.8In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After loggin...
CVE-2024-9415HIGH8.8A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th...
CVE-2024-9363HIGH7.5An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den...
CVE-2024-9362HIGH7.5An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerabilit...
CVE-2024-9340HIGH7.5A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause exces...
CVE-2024-9229HIGH7.5A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated a...
CVE-2024-9216HIGH8.1An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to ...
CVE-2024-9099HIGH8.1In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro...
CVE-2024-9096HIGH7.1In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending...
CVE-2024-9056HIGH7.5BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app...
CVE-2024-8999HIGH7.5lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi...
CVE-2024-8998HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ...
CVE-2024-8984HIGH7.5A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b...
CVE-2024-8966HIGH7.5A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv...
CVE-2024-8955HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo...
CVE-2024-8952HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap...
CVE-2024-8859HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co...
CVE-2024-8789HIGH7.5Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica...
CVE-2024-8765HIGH7.3In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c...
CVE-2024-8764HIGH7.5A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi...
CVE-2024-8763HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ...
CVE-2024-8616HIGH8.2In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s...
CVE-2024-8613HIGH8.8A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now