2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7046Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7045Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7044HIGH8.9A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ...
CVE-2024-7043HIGH8.8An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ...
CVE-2024-7040Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7039Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7036Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7035MEDIUM6.9In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET...
CVE-2024-7034Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7033Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-6986MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera...
CVE-2024-6982HIGH8.4A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability...
CVE-2024-6866HIGH7.5corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to ...
CVE-2024-6863MEDIUM6.5In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t...
CVE-2024-6854HIGH7.1In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an atta...
CVE-2024-6851HIGH7.5In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-spec...
CVE-2024-6844MEDIUM5.3A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the...
CVE-2024-6842HIGH7.5In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access s...
CVE-2024-6841MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)...
CVE-2024-6839MEDIUM5.3corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long...
CVE-2024-6838MEDIUM5.3In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la...
CVE-2024-6829CRITICAL9.1A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extr...
CVE-2024-6827HIGH7.5Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC s...
CVE-2024-6825HIGH8.8BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand...
CVE-2024-6583MEDIUM4.3A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now