2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7804 | — | — | — | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7779 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (Re... |
| CVE-2024-7776 | CRITICAL | 9.1 | 1.4% | Mar 20, 2025 | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows... |
| CVE-2024-7773 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45436. N... |
| CVE-2024-7771 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia... |
| CVE-2024-7768 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of s... |
| CVE-2024-7767 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir... |
| CVE-2024-7765 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cau... |
| CVE-2024-7764 | HIGH | 8.1 | 0.7% | Mar 20, 2025 | Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands ... |
| CVE-2024-7760 | CRITICAL | 9.6 | 0.5% | Mar 20, 2025 | aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulne... |
| CVE-2024-7476 | MEDIUM | 4.3 | 1.4% | Mar 20, 2025 | A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ... |
| CVE-2024-7058 | MEDIUM | 4.4 | 0.3% | Mar 20, 2025 | A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa... |
| CVE-2024-7053 | — | — | 0.7% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7046 | — | — | 0.4% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7045 | — | — | 0.4% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7044 | HIGH | 8.9 | 0.5% | Mar 20, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ... |
| CVE-2024-7043 | HIGH | 8.8 | 0.6% | Mar 20, 2025 | An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ... |
| CVE-2024-7040 | — | — | 0.6% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7039 | — | — | 0.6% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7036 | — | — | 0.8% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7035 | MEDIUM | 6.9 | 0.2% | Mar 20, 2025 | In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET... |
| CVE-2024-7034 | — | — | 2.5% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-7033 | — | — | 1.1% | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-6986 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera... |
| CVE-2024-6982 | HIGH | 8.4 | 0.4% | Mar 20, 2025 | A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now