2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12390 | HIGH | 8.8 | 1.5% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application suppo... |
| CVE-2024-12389 | HIGH | 8.8 | 1.5% | Mar 20, 2025 | A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the ext... |
| CVE-2024-12388 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) a... |
| CVE-2024-12387 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the s... |
| CVE-2024-12376 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the... |
| CVE-2024-12375 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a97... |
| CVE-2024-12374 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An... |
| CVE-2024-12217 | MEDIUM | 5.3 | 0.6% | Mar 20, 2025 | A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The i... |
| CVE-2024-12216 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, al... |
| CVE-2024-12215 | HIGH | 8.8 | 1.0% | Mar 20, 2025 | In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages... |
| CVE-2024-12074 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webu... |
| CVE-2024-12070 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release ... |
| CVE-2024-12068 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. T... |
| CVE-2024-12065 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacke... |
| CVE-2024-12063 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vu... |
| CVE-2024-12055 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be u... |
| CVE-2024-12048 | HIGH | 8.8 | 0.7% | Mar 20, 2025 | An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The appl... |
| CVE-2024-12044 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the u... |
| CVE-2024-12039 | HIGH | 8.1 | 0.6% | Mar 20, 2025 | langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess a... |
| CVE-2024-12029 | CRITICAL | 9.8 | 5.3% | Mar 20, 2025 | A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/i... |
| CVE-2024-11958 | CRITICAL | 9.8 | 1.3% | Mar 20, 2025 | A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specif... |
| CVE-2024-11850 | MEDIUM | 5.4 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is ... |
| CVE-2024-11824 | HIGH | 7.6 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log... |
| CVE-2024-11822 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due ... |
| CVE-2024-11821 | MEDIUM | 4.3 | 0.4% | Mar 20, 2025 | A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now