2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8065HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform un...
CVE-2024-8063HIGH7.5A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF mode...
CVE-2024-8062HIGH7.5A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint per...
CVE-2024-8061HIGH7.5In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, cau...
CVE-2024-8060——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8057MEDIUM4.3In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them t...
CVE-2024-8055HIGH7.5Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `C...
CVE-2024-8053HIGH8.2In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing u...
CVE-2024-8029MEDIUM6.1An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload m...
CVE-2024-8028HIGH7.5A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file ...
CVE-2024-8027MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious kno...
CVE-2024-8026HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9...
CVE-2024-8024HIGH7.5A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an att...
CVE-2024-8021MEDIUM6.1An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker t...
CVE-2024-8020HIGH7.5A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sendi...
CVE-2024-8019CRITICAL9.1In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows ...
CVE-2024-8018HIGH7.5A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file...
CVE-2024-8017CRITICAL9An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the...
CVE-2024-7999——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. N...
CVE-2024-7990——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7983HIGH7.5In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A malicio...
CVE-2024-7959——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7957CRITICAL9.1An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest versi...
CVE-2024-7819HIGH7.4A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat conten...
CVE-2024-7806——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now