2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12766HIGH7.5parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST...
CVE-2024-12761HIGH7.5A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerabil...
CVE-2024-12720HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe...
CVE-2024-12704HIGH7.5A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial ...
CVE-2024-12537HIGH7.5In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker...
CVE-2024-12534HIGH7.5In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and pass...
CVE-2024-12390HIGH8.8A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application suppo...
CVE-2024-12389HIGH8.8A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the ext...
CVE-2024-12376HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the...
CVE-2024-12216HIGH7.1A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, al...
CVE-2024-12215HIGH8.8In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages...
CVE-2024-12070HIGH7.5A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release ...
CVE-2024-12068HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. T...
CVE-2024-12065HIGH7.5A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacke...
CVE-2024-12063HIGH7.5A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vu...
CVE-2024-12055HIGH7.5A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be u...
CVE-2024-12048HIGH8.8An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The appl...
CVE-2024-12039HIGH8.1langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess a...
CVE-2024-11824HIGH7.6A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log...
CVE-2024-11822HIGH7.5langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due ...
CVE-2024-11603HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is presen...
CVE-2024-11602HIGH7.4A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on...
CVE-2024-11449HIGH7.5A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the...
CVE-2024-11302HIGH8A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, all...
CVE-2024-11172HIGH7.5A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now