2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6838MEDIUM5.3In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la...
CVE-2024-6583MEDIUM4.3A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker t...
CVE-2024-6577MEDIUM6.3In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metri...
CVE-2024-6483MEDIUM5.3A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or director...
CVE-2024-13060MEDIUM4.3A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profil...
CVE-2024-12910MEDIUM5.9A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an...
CVE-2024-12880MEDIUM6.5A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data query...
CVE-2024-12871MEDIUM5.4An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowl...
CVE-2024-12870MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main ...
CVE-2024-12869MEDIUM4.3In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view anot...
CVE-2024-12777MEDIUM5.9A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. Th...
CVE-2024-12775MEDIUM6.5langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for...
CVE-2024-12580MEDIUM5.3A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionI...
CVE-2024-12392MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The applicat...
CVE-2024-12391MEDIUM6.5A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (R...
CVE-2024-12388MEDIUM6.5A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) a...
CVE-2024-12387MEDIUM6.5A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the s...
CVE-2024-12375MEDIUM6.5A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a97...
CVE-2024-12374MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An...
CVE-2024-12217MEDIUM5.3A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The i...
CVE-2024-12074MEDIUM6.5A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webu...
CVE-2024-11850MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is ...
CVE-2024-11821MEDIUM4.3A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to...
CVE-2024-11441MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper ne...
CVE-2024-11301MEDIUM6.5In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now