2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7779HIGH7.5A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (Re...
CVE-2024-7768HIGH7.5A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of s...
CVE-2024-7767HIGH8.1An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir...
CVE-2024-7765HIGH7.5In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cau...
CVE-2024-7764HIGH8.1Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands ...
CVE-2024-7044HIGH8.9A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ...
CVE-2024-7043HIGH8.8An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ...
CVE-2024-7036HIGH7.5A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large tex...
CVE-2024-6982HIGH8.4A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability...
CVE-2024-6866HIGH7.5corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to ...
CVE-2024-6854HIGH7.1In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an atta...
CVE-2024-6851HIGH7.5In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-spec...
CVE-2024-6842HIGH7.5In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access s...
CVE-2024-6827HIGH7.5Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC s...
CVE-2024-6825HIGH8.8BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand...
CVE-2024-4023HIGH8.1A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a f...
CVE-2024-2292HIGH7.1Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.
CVE-2024-12911HIGH7.1A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito...
CVE-2024-12886HIGH7.5An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered w...
CVE-2024-12882HIGH7.5comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vu...
CVE-2024-12866HIGH7.5A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an att...
CVE-2024-12864HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2...
CVE-2024-12779HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is pre...
CVE-2024-12778HIGH7.5A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a larg...
CVE-2024-12776HIGH8.1In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now