2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11603HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is presen...
CVE-2024-11602HIGH7.4A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on...
CVE-2024-11449HIGH7.5A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the...
CVE-2024-11441MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper ne...
CVE-2024-11302HIGH8A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, all...
CVE-2024-11301MEDIUM6.5In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique c...
CVE-2024-11300MEDIUM6.5In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt...
CVE-2024-11173MEDIUM6.5An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead...
CVE-2024-11172HIGH7.5A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser...
CVE-2024-11171HIGH7.5In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses ...
CVE-2024-11170HIGH8.8A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of f...
CVE-2024-11169HIGH7.5An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs...
CVE-2024-11167MEDIUM5.3An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to ...
CVE-2024-11137HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/...
CVE-2024-11045CRITICAL9.6A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an ...
CVE-2024-11044MEDIUM6.1An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated at...
CVE-2024-11043HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai v...
CVE-2024-11042CRITICAL9.1In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion....
CVE-2024-11041CRITICAL9.8vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses ...
CVE-2024-11040——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8939. No...
CVE-2024-11039HIGH8.8A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt...
CVE-2024-11037MEDIUM6.5A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass...
CVE-2024-11033MEDIUM6.5A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The...
CVE-2024-11031HIGH7.5In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_...
CVE-2024-11030HIGH7.5GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plug...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now