2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12039 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess a... |
| CVE-2024-11824 | HIGH | 7.6 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log... |
| CVE-2024-11822 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due ... |
| CVE-2024-11603 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is presen... |
| CVE-2024-11602 | HIGH | 7.4 | 0.3% | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on... |
| CVE-2024-11449 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the... |
| CVE-2024-11302 | HIGH | 8 | 0.2% | Mar 20, 2025 | A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, all... |
| CVE-2024-11172 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser... |
| CVE-2024-11171 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses ... |
| CVE-2024-11170 | HIGH | 8.8 | 1.6% | Mar 20, 2025 | A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of f... |
| CVE-2024-11169 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs... |
| CVE-2024-11137 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/... |
| CVE-2024-11043 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai v... |
| CVE-2024-11039 | HIGH | 8.8 | 1.8% | Mar 20, 2025 | A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt... |
| CVE-2024-11031 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_... |
| CVE-2024-11030 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plug... |
| CVE-2024-10986 | HIGH | 8.8 | 0.8% | Mar 20, 2025 | GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This fu... |
| CVE-2024-10956 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CS... |
| CVE-2024-10954 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper ha... |
| CVE-2024-10950 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by pro... |
| CVE-2024-10935 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive ... |
| CVE-2024-10912 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnera... |
| CVE-2024-10907 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart bou... |
| CVE-2024-10906 | HIGH | 8.1 | 0.2% | Mar 20, 2025 | In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance ... |
| CVE-2024-10830 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/de... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now