2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12880MEDIUM6.5A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data query...
CVE-2024-12871MEDIUM5.4An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowl...
CVE-2024-12870MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main ...
CVE-2024-12869MEDIUM4.3In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view anot...
CVE-2024-12868——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-47874. N...
CVE-2024-12866HIGH7.5A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an att...
CVE-2024-12864HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2...
CVE-2024-12779HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is pre...
CVE-2024-12778HIGH7.5A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a larg...
CVE-2024-12777MEDIUM5.9A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. Th...
CVE-2024-12776HIGH8.1In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an ...
CVE-2024-12775MEDIUM6.5langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for...
CVE-2024-12766HIGH7.5parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST...
CVE-2024-12761HIGH7.5A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerabil...
CVE-2024-12760——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-4940. No...
CVE-2024-12759——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8966. No...
CVE-2024-12720HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe...
CVE-2024-12704HIGH7.5A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial ...
CVE-2024-12580MEDIUM5.3A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionI...
CVE-2024-12537——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-12534——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-12450CRITICAL9.8In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. ...
CVE-2024-12433CRITICAL9.8A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses ...
CVE-2024-12392MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The applicat...
CVE-2024-12391MEDIUM6.5A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (R...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now