2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12065 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacke... |
| CVE-2024-12063 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vu... |
| CVE-2024-12055 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be u... |
| CVE-2024-12048 | HIGH | 8.8 | 0.7% | Mar 20, 2025 | An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The appl... |
| CVE-2024-12044 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the u... |
| CVE-2024-12039 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess a... |
| CVE-2024-12029 | CRITICAL | 9.8 | 5.3% | Mar 20, 2025 | A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/i... |
| CVE-2024-11958 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specif... |
| CVE-2024-11850 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is ... |
| CVE-2024-11824 | HIGH | 7.6 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log... |
| CVE-2024-11822 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due ... |
| CVE-2024-11821 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to... |
| CVE-2024-11603 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is presen... |
| CVE-2024-11602 | HIGH | 7.4 | 0.3% | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on... |
| CVE-2024-11449 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the... |
| CVE-2024-11441 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper ne... |
| CVE-2024-11302 | HIGH | 8 | 0.2% | Mar 20, 2025 | A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, all... |
| CVE-2024-11301 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique c... |
| CVE-2024-11300 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt... |
| CVE-2024-11173 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead... |
| CVE-2024-11172 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser... |
| CVE-2024-11171 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses ... |
| CVE-2024-11170 | HIGH | 8.8 | 1.6% | Mar 20, 2025 | A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of f... |
| CVE-2024-11169 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs... |
| CVE-2024-11167 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now