2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7046 | — | — | 0.4% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7045 | — | — | 0.4% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7044 | HIGH | 8.9 | 0.5% | Mar 20, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ... |
| CVE-2024-7043 | HIGH | 8.8 | 0.6% | Mar 20, 2025 | An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ... |
| CVE-2024-7040 | — | — | 0.6% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7039 | — | — | 0.6% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7036 | — | — | 0.8% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7035 | MEDIUM | 6.9 | 0.2% | Mar 20, 2025 | In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET... |
| CVE-2024-7034 | — | — | 2.5% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7033 | — | — | 1.1% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-6986 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera... |
| CVE-2024-6982 | HIGH | 8.4 | 0.4% | Mar 20, 2025 | A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability... |
| CVE-2024-6866 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to ... |
| CVE-2024-6863 | MEDIUM | 6.5 | 0.3% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t... |
| CVE-2024-6854 | HIGH | 7.1 | 0.7% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an atta... |
| CVE-2024-6851 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-spec... |
| CVE-2024-6844 | MEDIUM | 5.3 | 0.3% | Mar 20, 2025 | A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the... |
| CVE-2024-6842 | HIGH | 7.5 | 29.2% | Mar 20, 2025 | In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access s... |
| CVE-2024-6841 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)... |
| CVE-2024-6839 | MEDIUM | 5.3 | 0.7% | Mar 20, 2025 | corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long... |
| CVE-2024-6838 | MEDIUM | 5.3 | 0.6% | Mar 20, 2025 | In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la... |
| CVE-2024-6829 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extr... |
| CVE-2024-6827 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC s... |
| CVE-2024-6825 | HIGH | 8.8 | 1.5% | Mar 20, 2025 | BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand... |
| CVE-2024-6583 | MEDIUM | 4.3 | 0.5% | Mar 20, 2025 | A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now