2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9439 | HIGH | 8.8 | 1.1% | Mar 20, 2025 | SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers ... |
| CVE-2024-9437 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in... |
| CVE-2024-9431 | HIGH | 8.8 | 0.6% | Mar 20, 2025 | In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After loggin... |
| CVE-2024-9415 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th... |
| CVE-2024-9363 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den... |
| CVE-2024-9362 | HIGH | 7.5 | 4.2% | Mar 20, 2025 | An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerabilit... |
| CVE-2024-9340 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause exces... |
| CVE-2024-9229 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated a... |
| CVE-2024-9216 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to ... |
| CVE-2024-9099 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro... |
| CVE-2024-9096 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending... |
| CVE-2024-9056 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app... |
| CVE-2024-8999 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi... |
| CVE-2024-8998 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ... |
| CVE-2024-8984 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b... |
| CVE-2024-8966 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv... |
| CVE-2024-8955 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo... |
| CVE-2024-8952 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap... |
| CVE-2024-8859 | HIGH | 7.5 | 2.5% | Mar 20, 2025 | A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co... |
| CVE-2024-8789 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica... |
| CVE-2024-8765 | HIGH | 7.3 | 0.8% | Mar 20, 2025 | In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c... |
| CVE-2024-8764 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi... |
| CVE-2024-8763 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ... |
| CVE-2024-8616 | HIGH | 8.2 | 0.5% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s... |
| CVE-2024-8613 | HIGH | 8.8 | 0.5% | Mar 20, 2025 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now