2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9311MEDIUM6.1A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload f...
CVE-2024-9308MEDIUM6.1An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker ...
CVE-2024-9159MEDIUM6.5An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability all...
CVE-2024-9107MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version...
CVE-2024-9098MEDIUM6.1In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe...
CVE-2024-9000MEDIUM6.5In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi...
CVE-2024-8982MEDIUM6.2A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se...
CVE-2024-8736MEDIUM6.5A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S...
CVE-2024-8556MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th...
CVE-2024-8400MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner...
CVE-2024-8251MEDIUM5.3A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th...
CVE-2024-8101MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ...
CVE-2024-8057MEDIUM4.3In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t...
CVE-2024-8029MEDIUM6.1An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m...
CVE-2024-8027MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno...
CVE-2024-8021MEDIUM6.1An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker t...
CVE-2024-7771MEDIUM6.5A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia...
CVE-2024-7476MEDIUM4.3A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ...
CVE-2024-7058MEDIUM4.4A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa...
CVE-2024-7035MEDIUM6.9In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET...
CVE-2024-6986MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera...
CVE-2024-6863MEDIUM6.5In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t...
CVE-2024-6844MEDIUM5.3A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the...
CVE-2024-6841MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)...
CVE-2024-6839MEDIUM5.3corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now