2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7779 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (Re... |
| CVE-2024-7768 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of s... |
| CVE-2024-7767 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir... |
| CVE-2024-7765 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cau... |
| CVE-2024-7764 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands ... |
| CVE-2024-7044 | HIGH | 8.9 | 0.5% | Mar 20, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ... |
| CVE-2024-7043 | HIGH | 8.8 | 0.6% | Mar 20, 2025 | An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ... |
| CVE-2024-7036 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large tex... |
| CVE-2024-6982 | HIGH | 8.4 | 0.4% | Mar 20, 2025 | A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability... |
| CVE-2024-6866 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to ... |
| CVE-2024-6854 | HIGH | 7.1 | 0.7% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an atta... |
| CVE-2024-6851 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-spec... |
| CVE-2024-6842 | HIGH | 7.5 | 29.2% | Mar 20, 2025 | In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access s... |
| CVE-2024-6827 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC s... |
| CVE-2024-6825 | HIGH | 8.8 | 1.5% | Mar 20, 2025 | BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand... |
| CVE-2024-4023 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a f... |
| CVE-2024-2292 | HIGH | 7.1 | 0.4% | Mar 20, 2025 | Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users. |
| CVE-2024-12911 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito... |
| CVE-2024-12886 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered w... |
| CVE-2024-12882 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vu... |
| CVE-2024-12866 | HIGH | 7.5 | 1.4% | Mar 20, 2025 | A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an att... |
| CVE-2024-12864 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2... |
| CVE-2024-12779 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is pre... |
| CVE-2024-12778 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a larg... |
| CVE-2024-12776 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now