2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10829HIGH7.5A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0...
CVE-2024-10821HIGH7.5A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (...
CVE-2024-10819HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to tri...
CVE-2024-10762HIGH8.1In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by...
CVE-2024-10718HIGH7.5In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca...
CVE-2024-10714HIGH7.5A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by addin...
CVE-2024-10713HIGH7.5A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle exce...
CVE-2024-10650HIGH7.5An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could ...
CVE-2024-10648HIGH8.2A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi...
CVE-2024-10624HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the g...
CVE-2024-10572HIGH7.5In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` p...
CVE-2024-10569HIGH7.5A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The ...
CVE-2024-10550HIGH7.5A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) att...
CVE-2024-10549HIGH7.5A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. ...
CVE-2024-10513HIGH7.2A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting...
CVE-2024-10275HIGH7.3In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access ...
CVE-2024-10272HIGH7.5lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any d...
CVE-2024-10267HIGH7.5An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can lea...
CVE-2024-10252HIGH7.2A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa...
CVE-2024-10225HIGH7.5A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large n...
CVE-2024-10188HIGH7.5A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS...
CVE-2024-10110HIGH7.5In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of t...
CVE-2024-10109HIGH8.3A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access...
CVE-2024-10051HIGH7.5Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in ...
CVE-2024-13881HIGH7.1The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now