2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10986 | HIGH | 8.8 | 0.8% | Mar 20, 2025 | GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This fu... |
| CVE-2024-10956 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CS... |
| CVE-2024-10955 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02.... |
| CVE-2024-10954 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper ha... |
| CVE-2024-10950 | HIGH | 8.8 | 1.3% | Mar 20, 2025 | In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by pro... |
| CVE-2024-10948 | MEDIUM | 6.5 | 0.8% | Mar 20, 2025 | A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the syste... |
| CVE-2024-10940 | MEDIUM | 5.3 | 0.4% | Mar 20, 2025 | A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us... |
| CVE-2024-10935 | HIGH | 7.5 | 0.8% | Mar 20, 2025 | automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive ... |
| CVE-2024-10912 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnera... |
| CVE-2024-10908 | MEDIUM | 6.1 | 0.8% | Mar 20, 2025 | An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect u... |
| CVE-2024-10907 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart bou... |
| CVE-2024-10906 | HIGH | 8.1 | 0.2% | Mar 20, 2025 | In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance ... |
| CVE-2024-10902 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Uplo... |
| CVE-2024-10901 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL que... |
| CVE-2024-10835 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queri... |
| CVE-2024-10834 | CRITICAL | 9.1 | 0.6% | Mar 20, 2025 | eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file ... |
| CVE-2024-10833 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for u... |
| CVE-2024-10831 | CRITICAL | 9.1 | 0.8% | Mar 20, 2025 | In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vu... |
| CVE-2024-10830 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/de... |
| CVE-2024-10829 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0... |
| CVE-2024-10821 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (... |
| CVE-2024-10819 | HIGH | 8.8 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to tri... |
| CVE-2024-10812 | MEDIUM | 6.1 | 0.6% | Mar 20, 2025 | An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is... |
| CVE-2024-10762 | HIGH | 8.1 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by... |
| CVE-2024-10727 | MEDIUM | 6.1 | 0.3% | Mar 20, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnera... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now