2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8524HIGH7.5A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerab...
CVE-2024-8501HIGH8.8An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0....
CVE-2024-8489HIGH8.8A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Re...
CVE-2024-8438HIGH7.5A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr...
CVE-2024-8249HIGH7.5mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ...
CVE-2024-8248HIGH7.2A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa...
CVE-2024-8238HIGH8.1In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro...
CVE-2024-8183HIGH7.6A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ...
CVE-2024-8099HIGH8.3A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t...
CVE-2024-8065HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform un...
CVE-2024-8063HIGH7.5A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF mode...
CVE-2024-8062HIGH7.5A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint per...
CVE-2024-8061HIGH7.5In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, cau...
CVE-2024-8060HIGH8.1OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows fo...
CVE-2024-8055HIGH7.5Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `C...
CVE-2024-8053HIGH8.2In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing u...
CVE-2024-8028HIGH7.5A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file ...
CVE-2024-8026HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9...
CVE-2024-8024HIGH7.5A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an att...
CVE-2024-8020HIGH7.5A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sendi...
CVE-2024-8018HIGH7.5A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file...
CVE-2024-7990HIGH8.4A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is pr...
CVE-2024-7983HIGH7.5In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A malicio...
CVE-2024-7819HIGH7.4A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat conten...
CVE-2024-7806HIGH8.8A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Sit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now