2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10648HIGH8.2A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi...
CVE-2024-10624HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the g...
CVE-2024-10572HIGH7.5In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` p...
CVE-2024-10569HIGH7.5A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The ...
CVE-2024-10553CRITICAL9.8A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitra...
CVE-2024-10550HIGH7.5A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) att...
CVE-2024-10549HIGH7.5A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. ...
CVE-2024-10513HIGH7.2A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting...
CVE-2024-10481MEDIUM6.5A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host...
CVE-2024-10457MEDIUM6.5Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito...
CVE-2024-10366MEDIUM6.5An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ...
CVE-2024-10363MEDIUM5.4In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ...
CVE-2024-10361CRITICAL9.1An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /ap...
CVE-2024-10359MEDIUM4.6In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca...
CVE-2024-10330MEDIUM6.5In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associa...
CVE-2024-10275HIGH7.3In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access ...
CVE-2024-10274MEDIUM6.5An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequ...
CVE-2024-10273MEDIUM6.5In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify...
CVE-2024-10272HIGH7.5lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any d...
CVE-2024-10267HIGH7.5An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can lea...
CVE-2024-10264CRITICAL9.8HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistenci...
CVE-2024-10252HIGH7.2A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa...
CVE-2024-10225HIGH7.5A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large n...
CVE-2024-10190CRITICAL9.8Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability ...
CVE-2024-10188HIGH7.5A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now