2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10901CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que...
CVE-2024-10835CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri...
CVE-2024-10834CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ...
CVE-2024-10833CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u...
CVE-2024-10831CRITICAL9.1In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu...
CVE-2024-10830HIGH8.2A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/de...
CVE-2024-10829HIGH7.5A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0...
CVE-2024-10821HIGH7.5A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (...
CVE-2024-10819HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to tri...
CVE-2024-10812MEDIUM6.1An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is...
CVE-2024-10762HIGH8.1In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by...
CVE-2024-10727MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera...
CVE-2024-10725MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ...
CVE-2024-10724MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA...
CVE-2024-10723MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10722MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta...
CVE-2024-10721MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10720MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t...
CVE-2024-10719MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ...
CVE-2024-10718HIGH7.5In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca...
CVE-2024-10714HIGH7.5A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by addin...
CVE-2024-10713HIGH7.5A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle exce...
CVE-2024-10707MEDIUM6.5gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the...
CVE-2024-10650HIGH7.5An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could ...
CVE-2024-10648HIGH8.2A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now