2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9099 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all pro... |
| CVE-2024-9098 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe... |
| CVE-2024-9096 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending... |
| CVE-2024-9095 | CRITICAL | 9.8 | 0.7% | Mar 20, 2025 | In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to... |
| CVE-2024-9070 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ... |
| CVE-2024-9056 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by app... |
| CVE-2024-9053 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ... |
| CVE-2024-9052 | — | — | — | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-9016 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. N... |
| CVE-2024-9000 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists wi... |
| CVE-2024-8999 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bi... |
| CVE-2024-8998 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server ... |
| CVE-2024-8984 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited b... |
| CVE-2024-8982 | MEDIUM | 6.2 | 0.7% | Mar 20, 2025 | A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local se... |
| CVE-2024-8966 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Serv... |
| CVE-2024-8958 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools action... |
| CVE-2024-8955 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allo... |
| CVE-2024-8954 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authenticatio... |
| CVE-2024-8953 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform ma... |
| CVE-2024-8952 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /ap... |
| CVE-2024-8898 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V1... |
| CVE-2024-8859 | HIGH | 7.5 | 2.5% | Mar 20, 2025 | A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, co... |
| CVE-2024-8789 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The applica... |
| CVE-2024-8769 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file d... |
| CVE-2024-8765 | HIGH | 7.3 | 0.8% | Mar 20, 2025 | In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now