2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24195HIGH7.5robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.
CVE-2024-24194HIGH7.5robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-p...
CVE-2024-5552HIGH7.5kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expr...
CVE-2024-5306HIGH7.8Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2024-5305HIGH7.8Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-5304HIGH7.8Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-5225HIGH7.2An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` en...
CVE-2024-5187HIGH8.8A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for a...
CVE-2024-5186HIGH7.2A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5...
CVE-2024-5133HIGH8.1In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tok...
CVE-2024-5130HIGH7.5An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows una...
CVE-2024-5129HIGH8.2A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets du...
CVE-2024-5128HIGH8.8An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to an...
CVE-2024-5124HIGH7.5A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comp...
CVE-2024-4888HIGH8.1BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on t...
CVE-2024-4881HIGH7.5A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlie...
CVE-2024-4851HIGH7.7A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which al...
CVE-2024-3150HIGH8.8In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Man...
CVE-2024-3149HIGH8.8A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This...
CVE-2024-3110HIGH8.7A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versio...
CVE-2024-3095HIGH7.7A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langch...
CVE-2024-37153HIGH7.5Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using ...
CVE-2024-36740HIGH7.5An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative num...
CVE-2024-36734HIGH7.5Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti...
CVE-2024-36732HIGH7.5An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is proce...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now