2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9056 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app... |
| CVE-2024-8999 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi... |
| CVE-2024-8998 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ... |
| CVE-2024-8984 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b... |
| CVE-2024-8966 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv... |
| CVE-2024-8955 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo... |
| CVE-2024-8952 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap... |
| CVE-2024-8859 | HIGH | 7.5 | 2.5% | Mar 20, 2025 | A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co... |
| CVE-2024-8789 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica... |
| CVE-2024-8765 | HIGH | 7.3 | 0.8% | Mar 20, 2025 | In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c... |
| CVE-2024-8764 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi... |
| CVE-2024-8763 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ... |
| CVE-2024-8616 | HIGH | 8.2 | 0.5% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s... |
| CVE-2024-8613 | HIGH | 8.8 | 0.5% | Mar 20, 2025 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'... |
| CVE-2024-8524 | HIGH | 7.5 | 1.2% | Mar 20, 2025 | A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerab... |
| CVE-2024-8501 | HIGH | 8.8 | 0.9% | Mar 20, 2025 | An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.... |
| CVE-2024-8489 | HIGH | 8.8 | 0.2% | Mar 20, 2025 | A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Re... |
| CVE-2024-8438 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr... |
| CVE-2024-8249 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ... |
| CVE-2024-8248 | HIGH | 7.2 | 0.8% | Mar 20, 2025 | A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa... |
| CVE-2024-8238 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro... |
| CVE-2024-8183 | HIGH | 7.6 | 0.2% | Mar 20, 2025 | A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ... |
| CVE-2024-8099 | HIGH | 8.3 | 0.3% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t... |
| CVE-2024-8065 | HIGH | 8.1 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform un... |
| CVE-2024-8063 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF mode... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now