2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7046MEDIUM4.3An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The a...
CVE-2024-7045MEDIUM4.3In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompt...
CVE-2024-7035MEDIUM6.9In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET...
CVE-2024-6986MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera...
CVE-2024-6863MEDIUM6.5In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t...
CVE-2024-6844MEDIUM5.3A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the...
CVE-2024-6841MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)...
CVE-2024-6839MEDIUM5.3corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long...
CVE-2024-6838MEDIUM5.3In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la...
CVE-2024-6583MEDIUM4.3A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker t...
CVE-2024-6577MEDIUM6.3In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metri...
CVE-2024-6483MEDIUM5.3A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or director...
CVE-2024-13060MEDIUM4.3A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profil...
CVE-2024-12910MEDIUM5.9A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an...
CVE-2024-12880MEDIUM6.5A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data query...
CVE-2024-12871MEDIUM5.4An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowl...
CVE-2024-12870MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main ...
CVE-2024-12869MEDIUM4.3In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view anot...
CVE-2024-12777MEDIUM5.9A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. Th...
CVE-2024-12775MEDIUM6.5langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for...
CVE-2024-12580MEDIUM5.3A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionI...
CVE-2024-12392MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The applicat...
CVE-2024-12391MEDIUM6.5A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (R...
CVE-2024-12388MEDIUM6.5A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) a...
CVE-2024-12387MEDIUM6.5A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now