2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9311 | MEDIUM | 6.1 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload f... |
| CVE-2024-9308 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker ... |
| CVE-2024-9159 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability all... |
| CVE-2024-9107 | MEDIUM | 5.4 | 0.5% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version... |
| CVE-2024-9098 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe... |
| CVE-2024-9000 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi... |
| CVE-2024-8982 | MEDIUM | 6.2 | 0.7% | Mar 20, 2025 | A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se... |
| CVE-2024-8736 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S... |
| CVE-2024-8556 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th... |
| CVE-2024-8400 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner... |
| CVE-2024-8251 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th... |
| CVE-2024-8101 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ... |
| CVE-2024-8057 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t... |
| CVE-2024-8029 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m... |
| CVE-2024-8027 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno... |
| CVE-2024-8021 | MEDIUM | 6.1 | 0.7% | Mar 20, 2025 | An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker t... |
| CVE-2024-7771 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia... |
| CVE-2024-7476 | MEDIUM | 4.3 | 1.4% | Mar 20, 2025 | A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ... |
| CVE-2024-7058 | MEDIUM | 4.4 | 0.3% | Mar 20, 2025 | A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa... |
| CVE-2024-7035 | MEDIUM | 6.9 | 0.2% | Mar 20, 2025 | In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET... |
| CVE-2024-6986 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera... |
| CVE-2024-6863 | MEDIUM | 6.5 | 0.3% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t... |
| CVE-2024-6844 | MEDIUM | 5.3 | 0.3% | Mar 20, 2025 | A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the... |
| CVE-2024-6841 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)... |
| CVE-2024-6839 | MEDIUM | 5.3 | 0.7% | Mar 20, 2025 | corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now