2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8487 | CRITICAL | 9.8 | 0.3% | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configurat... |
| CVE-2024-8438 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr... |
| CVE-2024-8400 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner... |
| CVE-2024-8251 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th... |
| CVE-2024-8249 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ... |
| CVE-2024-8248 | HIGH | 7.2 | 0.8% | Mar 20, 2025 | A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa... |
| CVE-2024-8238 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro... |
| CVE-2024-8196 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit... |
| CVE-2024-8183 | HIGH | 7.6 | 0.2% | Mar 20, 2025 | A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ... |
| CVE-2024-8156 | CRITICAL | 9.8 | 1.7% | Mar 20, 2025 | A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untru... |
| CVE-2024-8101 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ... |
| CVE-2024-8099 | HIGH | 8.3 | 0.3% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t... |
| CVE-2024-8065 | HIGH | 8.1 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform un... |
| CVE-2024-8063 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF mode... |
| CVE-2024-8062 | HIGH | 7.5 | 0.4% | Mar 20, 2025 | A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint per... |
| CVE-2024-8061 | HIGH | 7.5 | 0.4% | Mar 20, 2025 | In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, cau... |
| CVE-2024-8060 | — | — | 0.9% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-8057 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t... |
| CVE-2024-8055 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `C... |
| CVE-2024-8053 | HIGH | 8.2 | 0.6% | Mar 20, 2025 | In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing u... |
| CVE-2024-8029 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m... |
| CVE-2024-8028 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file ... |
| CVE-2024-8027 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno... |
| CVE-2024-8026 | HIGH | 8.1 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9... |
| CVE-2024-8024 | HIGH | 7.5 | 0.3% | Mar 20, 2025 | A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an att... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now