2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10986HIGH8.8GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This fu...
CVE-2024-10956HIGH7.1GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CS...
CVE-2024-10955MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02....
CVE-2024-10954HIGH8.8In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper ha...
CVE-2024-10950HIGH8.8In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by pro...
CVE-2024-10948MEDIUM6.5A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the syste...
CVE-2024-10940MEDIUM5.3A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us...
CVE-2024-10935HIGH7.5automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive ...
CVE-2024-10912HIGH7.5A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnera...
CVE-2024-10908MEDIUM6.1An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect u...
CVE-2024-10907HIGH7.5In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart bou...
CVE-2024-10906HIGH8.1In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance ...
CVE-2024-10902CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Uplo...
CVE-2024-10901CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que...
CVE-2024-10835CRITICAL9.8In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri...
CVE-2024-10834CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ...
CVE-2024-10833CRITICAL9.1eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u...
CVE-2024-10831CRITICAL9.1In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu...
CVE-2024-10830HIGH8.2A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/de...
CVE-2024-10829HIGH7.5A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0...
CVE-2024-10821HIGH7.5A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (...
CVE-2024-10819HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to tri...
CVE-2024-10812MEDIUM6.1An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is...
CVE-2024-10762HIGH8.1In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by...
CVE-2024-10727MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now