2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10901 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que... |
| CVE-2024-10835 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri... |
| CVE-2024-10834 | CRITICAL | 9.1 | 0.6% | Mar 20, 2025 | eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ... |
| CVE-2024-10833 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u... |
| CVE-2024-10831 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu... |
| CVE-2024-10830 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/de... |
| CVE-2024-10829 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0... |
| CVE-2024-10821 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (... |
| CVE-2024-10819 | HIGH | 8.8 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to tri... |
| CVE-2024-10812 | MEDIUM | 6.1 | 0.6% | Mar 20, 2025 | An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is... |
| CVE-2024-10762 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by... |
| CVE-2024-10727 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera... |
| CVE-2024-10725 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ... |
| CVE-2024-10724 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA... |
| CVE-2024-10723 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al... |
| CVE-2024-10722 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta... |
| CVE-2024-10721 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al... |
| CVE-2024-10720 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t... |
| CVE-2024-10719 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ... |
| CVE-2024-10718 | HIGH | 7.5 | 0.3% | Mar 20, 2025 | In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca... |
| CVE-2024-10714 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by addin... |
| CVE-2024-10713 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle exce... |
| CVE-2024-10707 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the... |
| CVE-2024-10650 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could ... |
| CVE-2024-10648 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now