2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9699MEDIUM5.4A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to...
CVE-2024-9617MEDIUM6.5An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verif...
CVE-2024-9612MEDIUM6.5In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search p...
CVE-2024-9447MEDIUM6.5An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisat...
CVE-2024-9418MEDIUM6.5In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in ...
CVE-2024-9365MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized a...
CVE-2024-9311MEDIUM6.1A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload f...
CVE-2024-9308MEDIUM6.1An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker ...
CVE-2024-9159MEDIUM6.5An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability all...
CVE-2024-9107MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version...
CVE-2024-9098MEDIUM6.1In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe...
CVE-2024-9000MEDIUM6.5In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi...
CVE-2024-8982MEDIUM6.2A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se...
CVE-2024-8736MEDIUM6.5A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S...
CVE-2024-8556MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th...
CVE-2024-8400MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner...
CVE-2024-8251MEDIUM5.3A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th...
CVE-2024-8101MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ...
CVE-2024-8057MEDIUM4.3In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t...
CVE-2024-8029MEDIUM6.1An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m...
CVE-2024-8027MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno...
CVE-2024-8021MEDIUM6.1An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker t...
CVE-2024-7771MEDIUM6.5A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia...
CVE-2024-7476MEDIUM4.3A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ...
CVE-2024-7058MEDIUM4.4A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now