2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8764HIGH7.5A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressi...
CVE-2024-8763HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in ...
CVE-2024-8736MEDIUM6.5A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (S...
CVE-2024-8616HIGH8.2In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s...
CVE-2024-8613HIGH8.8A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'...
CVE-2024-8581CRITICAL9.1A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any ...
CVE-2024-8556MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on th...
CVE-2024-8551CRITICAL9.1A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope vers...
CVE-2024-8537CRITICAL9.1A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerabilit...
CVE-2024-8524HIGH7.5A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerab...
CVE-2024-8502CRITICAL9.8A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (...
CVE-2024-8501HIGH8.8An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0....
CVE-2024-8489HIGH8.8A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Re...
CVE-2024-8487CRITICAL9.8A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configurat...
CVE-2024-8438HIGH7.5A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not pr...
CVE-2024-8400MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulner...
CVE-2024-8251MEDIUM5.3A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in th...
CVE-2024-8249HIGH7.5mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the ...
CVE-2024-8248HIGH7.2A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversa...
CVE-2024-8238HIGH8.1In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro...
CVE-2024-8196CRITICAL9.8In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit...
CVE-2024-8183HIGH7.6A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains ...
CVE-2024-8156CRITICAL9.8A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untru...
CVE-2024-8101MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. ...
CVE-2024-8099HIGH8.3A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now