2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8487CRITICAL9.8A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configurat...
CVE-2024-8438HIGH7.5A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr...
CVE-2024-8400MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner...
CVE-2024-8251MEDIUM5.3A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th...
CVE-2024-8249HIGH7.5mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ...
CVE-2024-8248HIGH7.2A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa...
CVE-2024-8238HIGH8.1In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro...
CVE-2024-8196CRITICAL9.8In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit...
CVE-2024-8183HIGH7.6A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ...
CVE-2024-8156CRITICAL9.8A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untru...
CVE-2024-8101MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ...
CVE-2024-8099HIGH8.3A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t...
CVE-2024-8065HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform un...
CVE-2024-8063HIGH7.5A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF mode...
CVE-2024-8062HIGH7.5A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint per...
CVE-2024-8061HIGH7.5In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, cau...
CVE-2024-8060Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8057MEDIUM4.3In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t...
CVE-2024-8055HIGH7.5Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `C...
CVE-2024-8053HIGH8.2In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing u...
CVE-2024-8029MEDIUM6.1An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m...
CVE-2024-8028HIGH7.5A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file ...
CVE-2024-8027MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno...
CVE-2024-8026HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9...
CVE-2024-8024HIGH7.5A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an att...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now