2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12039HIGH8.1langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess a...
CVE-2024-11824HIGH7.6A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log...
CVE-2024-11822HIGH7.5langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due ...
CVE-2024-11603HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is presen...
CVE-2024-11602HIGH7.4A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on...
CVE-2024-11449HIGH7.5A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the...
CVE-2024-11302HIGH8A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, all...
CVE-2024-11172HIGH7.5A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser...
CVE-2024-11171HIGH7.5In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses ...
CVE-2024-11170HIGH8.8A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of f...
CVE-2024-11169HIGH7.5An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs...
CVE-2024-11137HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/...
CVE-2024-11043HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai v...
CVE-2024-11039HIGH8.8A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt...
CVE-2024-11031HIGH7.5In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_...
CVE-2024-11030HIGH7.5GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plug...
CVE-2024-10986HIGH8.8GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This fu...
CVE-2024-10956HIGH7.1GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CS...
CVE-2024-10954HIGH8.8In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper ha...
CVE-2024-10950HIGH8.8In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by pro...
CVE-2024-10935HIGH7.5automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive ...
CVE-2024-10912HIGH7.5A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnera...
CVE-2024-10907HIGH7.5In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart bou...
CVE-2024-10906HIGH8.1In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance ...
CVE-2024-10830HIGH8.2A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/de...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now