2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12375MEDIUM6.5A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a97...
CVE-2024-12374MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An...
CVE-2024-12217MEDIUM5.3A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The i...
CVE-2024-12074MEDIUM6.5A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webu...
CVE-2024-11850MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is ...
CVE-2024-11821MEDIUM4.3A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to...
CVE-2024-11441MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper ne...
CVE-2024-11301MEDIUM6.5In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique c...
CVE-2024-11300MEDIUM6.5In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt...
CVE-2024-11173MEDIUM6.5An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead...
CVE-2024-11167MEDIUM5.3An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to ...
CVE-2024-11044MEDIUM6.1An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated at...
CVE-2024-11037MEDIUM6.5A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass...
CVE-2024-11033MEDIUM6.5A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The...
CVE-2024-10955MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02....
CVE-2024-10948MEDIUM6.5A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the syste...
CVE-2024-10940MEDIUM5.3A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us...
CVE-2024-10908MEDIUM6.1An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect u...
CVE-2024-10812MEDIUM6.1An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is...
CVE-2024-10727MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera...
CVE-2024-10725MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ...
CVE-2024-10724MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA...
CVE-2024-10723MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10722MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta...
CVE-2024-10721MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now