2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8764 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi... |
| CVE-2024-8763 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ... |
| CVE-2024-8736 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S... |
| CVE-2024-8616 | HIGH | 8.2 | 0.5% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s... |
| CVE-2024-8613 | HIGH | 8.8 | 0.5% | Mar 20, 2025 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'... |
| CVE-2024-8581 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any ... |
| CVE-2024-8556 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th... |
| CVE-2024-8551 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope vers... |
| CVE-2024-8537 | CRITICAL | 9.1 | 1.0% | Mar 20, 2025 | A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerabilit... |
| CVE-2024-8524 | HIGH | 7.5 | 1.2% | Mar 20, 2025 | A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerab... |
| CVE-2024-8502 | CRITICAL | 9.8 | 1.6% | Mar 20, 2025 | A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (... |
| CVE-2024-8501 | HIGH | 8.8 | 0.9% | Mar 20, 2025 | An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.... |
| CVE-2024-8489 | HIGH | 8.8 | 0.2% | Mar 20, 2025 | A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Re... |
| CVE-2024-8487 | CRITICAL | 9.8 | 0.3% | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configurat... |
| CVE-2024-8438 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr... |
| CVE-2024-8400 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner... |
| CVE-2024-8251 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th... |
| CVE-2024-8249 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ... |
| CVE-2024-8248 | HIGH | 7.2 | 0.8% | Mar 20, 2025 | A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa... |
| CVE-2024-8238 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro... |
| CVE-2024-8196 | CRITICAL | 9.8 | 0.8% | Mar 20, 2025 | In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit... |
| CVE-2024-8183 | HIGH | 7.6 | 0.2% | Mar 20, 2025 | A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ... |
| CVE-2024-8156 | CRITICAL | 9.8 | 1.7% | Mar 20, 2025 | A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untru... |
| CVE-2024-8101 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ... |
| CVE-2024-8099 | HIGH | 8.3 | 0.3% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now