2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9056HIGH7.5BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app...
CVE-2024-8999HIGH7.5lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi...
CVE-2024-8998HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ...
CVE-2024-8984HIGH7.5A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b...
CVE-2024-8966HIGH7.5A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv...
CVE-2024-8955HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo...
CVE-2024-8952HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap...
CVE-2024-8859HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co...
CVE-2024-8789HIGH7.5Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica...
CVE-2024-8765HIGH7.3In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c...
CVE-2024-8764HIGH7.5A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi...
CVE-2024-8763HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ...
CVE-2024-8616HIGH8.2In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s...
CVE-2024-8613HIGH8.8A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'...
CVE-2024-8524HIGH7.5A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerab...
CVE-2024-8501HIGH8.8An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0....
CVE-2024-8489HIGH8.8A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Re...
CVE-2024-8438HIGH7.5A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr...
CVE-2024-8249HIGH7.5mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ...
CVE-2024-8248HIGH7.2A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa...
CVE-2024-8238HIGH8.1In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro...
CVE-2024-8183HIGH7.6A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ...
CVE-2024-8099HIGH8.3A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t...
CVE-2024-8065HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform un...
CVE-2024-8063HIGH7.5A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF mode...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now