2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7046 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The a... |
| CVE-2024-7045 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompt... |
| CVE-2024-7035 | MEDIUM | 6.9 | 0.2% | Mar 20, 2025 | In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET... |
| CVE-2024-6986 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera... |
| CVE-2024-6863 | MEDIUM | 6.5 | 0.3% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t... |
| CVE-2024-6844 | MEDIUM | 5.3 | 0.3% | Mar 20, 2025 | A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the... |
| CVE-2024-6841 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)... |
| CVE-2024-6839 | MEDIUM | 5.3 | 0.7% | Mar 20, 2025 | corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long... |
| CVE-2024-6838 | MEDIUM | 5.3 | 0.6% | Mar 20, 2025 | In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la... |
| CVE-2024-6583 | MEDIUM | 4.3 | 0.5% | Mar 20, 2025 | A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker t... |
| CVE-2024-6577 | MEDIUM | 6.3 | 0.4% | Mar 20, 2025 | In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metri... |
| CVE-2024-6483 | MEDIUM | 5.3 | 0.8% | Mar 20, 2025 | A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or director... |
| CVE-2024-13060 | MEDIUM | 4.3 | 0.5% | Mar 20, 2025 | A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profil... |
| CVE-2024-12910 | MEDIUM | 5.9 | 0.6% | Mar 20, 2025 | A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an... |
| CVE-2024-12880 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data query... |
| CVE-2024-12871 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowl... |
| CVE-2024-12870 | MEDIUM | 5.4 | 0.5% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main ... |
| CVE-2024-12869 | MEDIUM | 4.3 | 0.5% | Mar 20, 2025 | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view anot... |
| CVE-2024-12777 | MEDIUM | 5.9 | 0.4% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. Th... |
| CVE-2024-12775 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for... |
| CVE-2024-12580 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionI... |
| CVE-2024-12392 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The applicat... |
| CVE-2024-12391 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (R... |
| CVE-2024-12388 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) a... |
| CVE-2024-12387 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now