2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6866HIGH7.5corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to ...
CVE-2024-6863MEDIUM6.5In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on t...
CVE-2024-6854HIGH7.1In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an atta...
CVE-2024-6851HIGH7.5In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-spec...
CVE-2024-6844MEDIUM5.3A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the...
CVE-2024-6842HIGH7.5In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access s...
CVE-2024-6841MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502)...
CVE-2024-6839MEDIUM5.3corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes long...
CVE-2024-6838MEDIUM5.3In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la...
CVE-2024-6829CRITICAL9.1A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extr...
CVE-2024-6827HIGH7.5Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC s...
CVE-2024-6825HIGH8.8BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the hand...
CVE-2024-6583MEDIUM4.3A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker t...
CVE-2024-6577MEDIUM6.3In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metri...
CVE-2024-6483MEDIUM5.3A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or director...
CVE-2024-5752CRITICAL9.1A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the af...
CVE-2024-4990CRITICAL9.1In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does ...
CVE-2024-4023HIGH8.1A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a f...
CVE-2024-2292HIGH7.1Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.
CVE-2024-13060MEDIUM4.3A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profil...
CVE-2024-12911HIGH7.1A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito...
CVE-2024-12910MEDIUM5.9A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an...
CVE-2024-12909CRITICAL9.8A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for ...
CVE-2024-12886HIGH7.5An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered w...
CVE-2024-12882HIGH7.5comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now