2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9415 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th... |
| CVE-2024-9365 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized a... |
| CVE-2024-9363 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den... |
| CVE-2024-9362 | HIGH | 7.5 | 4.2% | Mar 20, 2025 | An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerabilit... |
| CVE-2024-9340 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause exces... |
| CVE-2024-9311 | MEDIUM | 6.1 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload f... |
| CVE-2024-9309 | CRITICAL | 9.3 | 0.5% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro... |
| CVE-2024-9308 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker ... |
| CVE-2024-9229 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated a... |
| CVE-2024-9216 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to ... |
| CVE-2024-9159 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability all... |
| CVE-2024-9107 | MEDIUM | 5.4 | 0.5% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version... |
| CVE-2024-9099 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro... |
| CVE-2024-9098 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe... |
| CVE-2024-9096 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending... |
| CVE-2024-9095 | CRITICAL | 9.8 | 0.7% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to... |
| CVE-2024-9070 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ... |
| CVE-2024-9056 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app... |
| CVE-2024-9053 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ... |
| CVE-2024-9052 | — | — | — | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-9016 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. N... |
| CVE-2024-9000 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi... |
| CVE-2024-8999 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi... |
| CVE-2024-8998 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ... |
| CVE-2024-8984 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now