2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9415HIGH8.8A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th...
CVE-2024-9365MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized a...
CVE-2024-9363HIGH7.5An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den...
CVE-2024-9362HIGH7.5An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerabilit...
CVE-2024-9340HIGH7.5A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause exces...
CVE-2024-9311MEDIUM6.1A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload f...
CVE-2024-9309CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro...
CVE-2024-9308MEDIUM6.1An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker ...
CVE-2024-9229HIGH7.5A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated a...
CVE-2024-9216HIGH8.1An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to ...
CVE-2024-9159MEDIUM6.5An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability all...
CVE-2024-9107MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version...
CVE-2024-9099HIGH8.1In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro...
CVE-2024-9098MEDIUM6.1In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe...
CVE-2024-9096HIGH7.1In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending...
CVE-2024-9095CRITICAL9.8In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to...
CVE-2024-9070CRITICAL9.8A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ...
CVE-2024-9056HIGH7.5BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app...
CVE-2024-9053CRITICAL9.8vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ...
CVE-2024-9052Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-9016Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. N...
CVE-2024-9000MEDIUM6.5In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi...
CVE-2024-8999HIGH7.5lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi...
CVE-2024-8998HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ...
CVE-2024-8984HIGH7.5A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now