2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8982MEDIUM6.2A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se...
CVE-2024-8966HIGH7.5A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv...
CVE-2024-8958CRITICAL9.8In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools action...
CVE-2024-8955HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo...
CVE-2024-8954CRITICAL9.8In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authenticatio...
CVE-2024-8953CRITICAL9.8In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform ma...
CVE-2024-8952HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap...
CVE-2024-8898CRITICAL9.8A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V1...
CVE-2024-8859HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co...
CVE-2024-8789HIGH7.5Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica...
CVE-2024-8769CRITICAL9.1A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file d...
CVE-2024-8765HIGH7.3In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c...
CVE-2024-8764HIGH7.5A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi...
CVE-2024-8763HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ...
CVE-2024-8736MEDIUM6.5A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S...
CVE-2024-8616HIGH8.2In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s...
CVE-2024-8613HIGH8.8A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'...
CVE-2024-8581CRITICAL9.1A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any ...
CVE-2024-8556MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th...
CVE-2024-8551CRITICAL9.1A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope vers...
CVE-2024-8537CRITICAL9.1A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerabilit...
CVE-2024-8524HIGH7.5A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerab...
CVE-2024-8502CRITICAL9.8A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (...
CVE-2024-8501HIGH8.8An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0....
CVE-2024-8489HIGH8.8A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Re...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now