2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10829 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0... |
| CVE-2024-10821 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (... |
| CVE-2024-10819 | HIGH | 8.8 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to tri... |
| CVE-2024-10762 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by... |
| CVE-2024-10718 | HIGH | 7.5 | 0.3% | Mar 20, 2025 | In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca... |
| CVE-2024-10714 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by addin... |
| CVE-2024-10713 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle exce... |
| CVE-2024-10650 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could ... |
| CVE-2024-10648 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi... |
| CVE-2024-10624 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the g... |
| CVE-2024-10572 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` p... |
| CVE-2024-10569 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The ... |
| CVE-2024-10550 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) att... |
| CVE-2024-10549 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. ... |
| CVE-2024-10513 | HIGH | 7.2 | 0.8% | Mar 20, 2025 | A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting... |
| CVE-2024-10275 | HIGH | 7.3 | 0.5% | Mar 20, 2025 | In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access ... |
| CVE-2024-10272 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any d... |
| CVE-2024-10267 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can lea... |
| CVE-2024-10252 | HIGH | 7.2 | 0.7% | Mar 20, 2025 | A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa... |
| CVE-2024-10225 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large n... |
| CVE-2024-10188 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS... |
| CVE-2024-10110 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of t... |
| CVE-2024-10109 | HIGH | 8.3 | 0.5% | Mar 20, 2025 | A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access... |
| CVE-2024-10051 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in ... |
| CVE-2024-13881 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now