2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7804——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7779HIGH7.5A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (Re...
CVE-2024-7776CRITICAL9.1A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows...
CVE-2024-7773——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45436. N...
CVE-2024-7771MEDIUM6.5A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia...
CVE-2024-7768HIGH7.5A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of s...
CVE-2024-7767HIGH8.1An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir...
CVE-2024-7765HIGH7.5In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cau...
CVE-2024-7764HIGH8.1Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands ...
CVE-2024-7760CRITICAL9.6aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulne...
CVE-2024-7476MEDIUM4.3A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows ...
CVE-2024-7058MEDIUM4.4A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sa...
CVE-2024-7053——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7046——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7045——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7044HIGH8.9A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui ...
CVE-2024-7043HIGH8.8An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. ...
CVE-2024-7040——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7039——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7036——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7035MEDIUM6.9In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET...
CVE-2024-7034——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-7033——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-6986MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnera...
CVE-2024-6982HIGH8.4A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now