2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11300 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt... |
| CVE-2024-11173 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead... |
| CVE-2024-11167 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to ... |
| CVE-2024-11044 | MEDIUM | 6.1 | 0.8% | Mar 20, 2025 | An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated at... |
| CVE-2024-11037 | MEDIUM | 6.5 | 1.0% | Mar 20, 2025 | A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass... |
| CVE-2024-11033 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The... |
| CVE-2024-10955 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02.... |
| CVE-2024-10948 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the syste... |
| CVE-2024-10940 | MEDIUM | 5.3 | 0.4% | Mar 20, 2025 | A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us... |
| CVE-2024-10908 | MEDIUM | 6.1 | 0.8% | Mar 20, 2025 | An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect u... |
| CVE-2024-10812 | MEDIUM | 6.1 | 0.6% | Mar 20, 2025 | An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is... |
| CVE-2024-10727 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera... |
| CVE-2024-10725 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ... |
| CVE-2024-10724 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA... |
| CVE-2024-10723 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al... |
| CVE-2024-10722 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta... |
| CVE-2024-10721 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al... |
| CVE-2024-10720 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t... |
| CVE-2024-10719 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ... |
| CVE-2024-10707 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the... |
| CVE-2024-10481 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host... |
| CVE-2024-10457 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito... |
| CVE-2024-10366 | MEDIUM | 6.5 | 0.3% | Mar 20, 2025 | An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ... |
| CVE-2024-10363 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ... |
| CVE-2024-10359 | MEDIUM | 4.6 | 0.3% | Mar 20, 2025 | In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now