2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11603 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is presen... |
| CVE-2024-11602 | HIGH | 7.4 | 0.3% | Mar 20, 2025 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on... |
| CVE-2024-11449 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the... |
| CVE-2024-11441 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper ne... |
| CVE-2024-11302 | HIGH | 8 | 0.2% | Mar 20, 2025 | A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, all... |
| CVE-2024-11301 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique c... |
| CVE-2024-11300 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt... |
| CVE-2024-11173 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead... |
| CVE-2024-11172 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser... |
| CVE-2024-11171 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses ... |
| CVE-2024-11170 | HIGH | 8.8 | 1.6% | Mar 20, 2025 | A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of f... |
| CVE-2024-11169 | HIGH | 7.5 | 0.9% | Mar 20, 2025 | An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs... |
| CVE-2024-11167 | MEDIUM | 5.3 | 0.5% | Mar 20, 2025 | An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to ... |
| CVE-2024-11137 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/... |
| CVE-2024-11045 | CRITICAL | 9.6 | 0.4% | Mar 20, 2025 | A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an ... |
| CVE-2024-11044 | MEDIUM | 6.1 | 0.8% | Mar 20, 2025 | An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated at... |
| CVE-2024-11043 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai v... |
| CVE-2024-11042 | CRITICAL | 9.1 | 1.3% | Mar 20, 2025 | In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion.... |
| CVE-2024-11041 | CRITICAL | 9.8 | 1.4% | Mar 20, 2025 | vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses ... |
| CVE-2024-11040 | — | — | — | Mar 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8939. No... |
| CVE-2024-11039 | HIGH | 8.8 | 1.8% | Mar 20, 2025 | A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt... |
| CVE-2024-11037 | MEDIUM | 6.5 | 1.0% | Mar 20, 2025 | A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass... |
| CVE-2024-11033 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The... |
| CVE-2024-11031 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_... |
| CVE-2024-11030 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plug... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now