2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6577MEDIUM6.3In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metri...
CVE-2024-6483MEDIUM5.3A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or director...
CVE-2024-5752CRITICAL9.1A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the af...
CVE-2024-4990CRITICAL9.1In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does ...
CVE-2024-4023HIGH8.1A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a f...
CVE-2024-2292HIGH7.1Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.
CVE-2024-13060MEDIUM4.3A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profil...
CVE-2024-12911HIGH7.1A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito...
CVE-2024-12910MEDIUM5.9A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an...
CVE-2024-12909CRITICAL9.8A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for ...
CVE-2024-12886HIGH7.5An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered w...
CVE-2024-12882HIGH7.5comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vu...
CVE-2024-12880MEDIUM6.5A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data query...
CVE-2024-12871MEDIUM5.4An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowl...
CVE-2024-12870MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main ...
CVE-2024-12869MEDIUM4.3In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view anot...
CVE-2024-12868Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-47874. N...
CVE-2024-12866HIGH7.5A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an att...
CVE-2024-12864HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2...
CVE-2024-12779HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is pre...
CVE-2024-12778HIGH7.5A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a larg...
CVE-2024-12777MEDIUM5.9A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. Th...
CVE-2024-12776HIGH8.1In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an ...
CVE-2024-12775MEDIUM6.5langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for...
CVE-2024-12766HIGH7.5parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now