2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8062HIGH7.5A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint per...
CVE-2024-8061HIGH7.5In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, cau...
CVE-2024-8055HIGH7.5Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `C...
CVE-2024-8053HIGH8.2In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing u...
CVE-2024-8028HIGH7.5A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file ...
CVE-2024-8026HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9...
CVE-2024-8024HIGH7.5A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an att...
CVE-2024-8020HIGH7.5A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sendi...
CVE-2024-8018HIGH7.5A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file...
CVE-2024-7983HIGH7.5In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A malicio...
CVE-2024-7819HIGH7.4A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat conten...
CVE-2024-7779HIGH7.5A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (Re...
CVE-2024-7768HIGH7.5A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of s...
CVE-2024-7767HIGH8.1An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir...
CVE-2024-7765HIGH7.5In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cau...
CVE-2024-7764HIGH8.1Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands ...
CVE-2024-7044HIGH8.9A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ...
CVE-2024-7043HIGH8.8An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ...
CVE-2024-6982HIGH8.4A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability...
CVE-2024-6866HIGH7.5corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to ...
CVE-2024-6854HIGH7.1In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an atta...
CVE-2024-6851HIGH7.5In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-spec...
CVE-2024-6842HIGH7.5In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access s...
CVE-2024-6827HIGH7.5Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC s...
CVE-2024-6825HIGH8.8BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now