2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11300MEDIUM6.5In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt...
CVE-2024-11173MEDIUM6.5An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead...
CVE-2024-11167MEDIUM5.3An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to ...
CVE-2024-11044MEDIUM6.1An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated at...
CVE-2024-11037MEDIUM6.5A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass...
CVE-2024-11033MEDIUM6.5A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The...
CVE-2024-10955MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02....
CVE-2024-10948MEDIUM6.5A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the syste...
CVE-2024-10940MEDIUM5.3A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us...
CVE-2024-10908MEDIUM6.1An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect u...
CVE-2024-10812MEDIUM6.1An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is...
CVE-2024-10727MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera...
CVE-2024-10725MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ...
CVE-2024-10724MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA...
CVE-2024-10723MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10722MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta...
CVE-2024-10721MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10720MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t...
CVE-2024-10719MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ...
CVE-2024-10707MEDIUM6.5gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the...
CVE-2024-10481MEDIUM6.5A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host...
CVE-2024-10457MEDIUM6.5Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito...
CVE-2024-10366MEDIUM6.5An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ...
CVE-2024-10363MEDIUM5.4In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ...
CVE-2024-10359MEDIUM4.6In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now