2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9099HIGH8.1In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro...
CVE-2024-9098MEDIUM6.1In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe...
CVE-2024-9096HIGH7.1In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending...
CVE-2024-9095CRITICAL9.8In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to...
CVE-2024-9070CRITICAL9.8A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ...
CVE-2024-9056HIGH7.5BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app...
CVE-2024-9053CRITICAL9.8vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ...
CVE-2024-9052——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-9016——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. N...
CVE-2024-9000MEDIUM6.5In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi...
CVE-2024-8999HIGH7.5lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi...
CVE-2024-8998HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ...
CVE-2024-8984HIGH7.5A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b...
CVE-2024-8982MEDIUM6.2A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se...
CVE-2024-8966HIGH7.5A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv...
CVE-2024-8958CRITICAL9.8In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools action...
CVE-2024-8955HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo...
CVE-2024-8954CRITICAL9.8In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authenticatio...
CVE-2024-8953CRITICAL9.8In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform ma...
CVE-2024-8952HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap...
CVE-2024-8898CRITICAL9.8A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V1...
CVE-2024-8859HIGH7.5A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co...
CVE-2024-8789HIGH7.5Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica...
CVE-2024-8769CRITICAL9.1A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file d...
CVE-2024-8765HIGH7.3In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now