2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9699 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to... |
| CVE-2024-9617 | MEDIUM | 6.5 | 1.6% | Mar 20, 2025 | An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verif... |
| CVE-2024-9612 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search p... |
| CVE-2024-9447 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisat... |
| CVE-2024-9418 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in ... |
| CVE-2024-9365 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized a... |
| CVE-2024-9311 | MEDIUM | 6.1 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload f... |
| CVE-2024-9308 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker ... |
| CVE-2024-9159 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability all... |
| CVE-2024-9107 | MEDIUM | 5.4 | 0.5% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version... |
| CVE-2024-9098 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe... |
| CVE-2024-9000 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi... |
| CVE-2024-8982 | MEDIUM | 6.2 | 0.7% | Mar 20, 2025 | A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se... |
| CVE-2024-8736 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S... |
| CVE-2024-8556 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th... |
| CVE-2024-8400 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner... |
| CVE-2024-8251 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th... |
| CVE-2024-8101 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ... |
| CVE-2024-8057 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t... |
| CVE-2024-8029 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m... |
| CVE-2024-8027 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno... |
| CVE-2024-8021 | MEDIUM | 6.1 | 0.7% | Mar 20, 2025 | An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker t... |
| CVE-2024-7771 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia... |
| CVE-2024-7476 | MEDIUM | 4.3 | 1.4% | Mar 20, 2025 | A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ... |
| CVE-2024-7058 | MEDIUM | 4.4 | 0.3% | Mar 20, 2025 | A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now