2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8021MEDIUM6.1An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker t...
CVE-2024-8020HIGH7.5A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sendi...
CVE-2024-8019CRITICAL9.1In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows ...
CVE-2024-8018HIGH7.5A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file...
CVE-2024-8017CRITICAL9An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the...
CVE-2024-7999Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. N...
CVE-2024-7990Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7983HIGH7.5In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A malicio...
CVE-2024-7959Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7957CRITICAL9.1An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest versi...
CVE-2024-7819HIGH7.4A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat conten...
CVE-2024-7806HIGH8.8A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Sit...
CVE-2024-7804Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7779HIGH7.5A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (Re...
CVE-2024-7776CRITICAL9.1A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows...
CVE-2024-7773Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45436. N...
CVE-2024-7771MEDIUM6.5A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia...
CVE-2024-7768HIGH7.5A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of s...
CVE-2024-7767HIGH8.1An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir...
CVE-2024-7765HIGH7.5In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cau...
CVE-2024-7764HIGH8.1Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands ...
CVE-2024-7760CRITICAL9.6aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulne...
CVE-2024-7476MEDIUM4.3A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ...
CVE-2024-7058MEDIUM4.4A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa...
CVE-2024-7053Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now