2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4023 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a f... |
| CVE-2024-2292 | HIGH | 7.1 | 0.4% | Mar 20, 2025 | Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users. |
| CVE-2024-12911 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito... |
| CVE-2024-12886 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered w... |
| CVE-2024-12882 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vu... |
| CVE-2024-12866 | HIGH | 7.5 | 1.4% | Mar 20, 2025 | A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an att... |
| CVE-2024-12864 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2... |
| CVE-2024-12779 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is pre... |
| CVE-2024-12778 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a larg... |
| CVE-2024-12776 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an ... |
| CVE-2024-12766 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST... |
| CVE-2024-12761 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerabil... |
| CVE-2024-12720 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe... |
| CVE-2024-12704 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial ... |
| CVE-2024-12390 | HIGH | 8.8 | 1.5% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application suppo... |
| CVE-2024-12389 | HIGH | 8.8 | 1.5% | Mar 20, 2025 | A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the ext... |
| CVE-2024-12376 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the... |
| CVE-2024-12216 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, al... |
| CVE-2024-12215 | HIGH | 8.8 | 1.0% | Mar 20, 2025 | In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages... |
| CVE-2024-12070 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release ... |
| CVE-2024-12068 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. T... |
| CVE-2024-12065 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacke... |
| CVE-2024-12063 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vu... |
| CVE-2024-12055 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be u... |
| CVE-2024-12048 | HIGH | 8.8 | 0.7% | Mar 20, 2025 | An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The appl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now