2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6577 | MEDIUM | 6.3 | 0.4% | Mar 20, 2025 | In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metri... |
| CVE-2024-6483 | MEDIUM | 5.3 | 0.8% | Mar 20, 2025 | A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or director... |
| CVE-2024-5752 | CRITICAL | 9.1 | 1.4% | Mar 20, 2025 | A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the af... |
| CVE-2024-4990 | CRITICAL | 9.1 | 79.4% | Mar 20, 2025 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does ... |
| CVE-2024-4023 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a f... |
| CVE-2024-2292 | HIGH | 7.1 | 0.4% | Mar 20, 2025 | Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users. |
| CVE-2024-13060 | MEDIUM | 4.3 | 0.5% | Mar 20, 2025 | A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profil... |
| CVE-2024-12911 | HIGH | 7.1 | 0.5% | Mar 20, 2025 | A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito... |
| CVE-2024-12910 | MEDIUM | 5.9 | 0.6% | Mar 20, 2025 | A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an... |
| CVE-2024-12909 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for ... |
| CVE-2024-12886 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered w... |
| CVE-2024-12882 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vu... |
| CVE-2024-12880 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data query... |
| CVE-2024-12871 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowl... |
| CVE-2024-12870 | MEDIUM | 5.4 | 0.5% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main ... |
| CVE-2024-12869 | MEDIUM | 4.3 | 0.5% | Mar 20, 2025 | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view anot... |
| CVE-2024-12868 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-47874. N... |
| CVE-2024-12866 | HIGH | 7.5 | 1.4% | Mar 20, 2025 | A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an att... |
| CVE-2024-12864 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2... |
| CVE-2024-12779 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is pre... |
| CVE-2024-12778 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a larg... |
| CVE-2024-12777 | MEDIUM | 5.9 | 0.4% | Mar 20, 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. Th... |
| CVE-2024-12776 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an ... |
| CVE-2024-12775 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for... |
| CVE-2024-12766 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now