2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10648 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi... |
| CVE-2024-10624 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the g... |
| CVE-2024-10572 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` p... |
| CVE-2024-10569 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The ... |
| CVE-2024-10550 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) att... |
| CVE-2024-10549 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. ... |
| CVE-2024-10513 | HIGH | 7.2 | 0.8% | Mar 20, 2025 | A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting... |
| CVE-2024-10275 | HIGH | 7.3 | 0.5% | Mar 20, 2025 | In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access ... |
| CVE-2024-10272 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any d... |
| CVE-2024-10267 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can lea... |
| CVE-2024-10252 | HIGH | 7.2 | 0.7% | Mar 20, 2025 | A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa... |
| CVE-2024-10225 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large n... |
| CVE-2024-10188 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS... |
| CVE-2024-10110 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of t... |
| CVE-2024-10109 | HIGH | 8.3 | 0.5% | Mar 20, 2025 | A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access... |
| CVE-2024-10051 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in ... |
| CVE-2024-13881 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13880 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13878 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13877 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before ou... |
| CVE-2024-13876 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13875 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-51459 | HIGH | 7.8 | 0.1% | Mar 19, 2025 | IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handl... |
| CVE-2024-42176 | HIGH | 8 | 0.2% | Mar 19, 2025 | HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous ... |
| CVE-2024-55551 | HIGH | 8.3 | 0.6% | Mar 19, 2025 | An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now