2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10725MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ...
CVE-2024-10724MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA...
CVE-2024-10723MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10722MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta...
CVE-2024-10721MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al...
CVE-2024-10720MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t...
CVE-2024-10719MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ...
CVE-2024-10718HIGH7.5In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca...
CVE-2024-10714HIGH7.5A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by addin...
CVE-2024-10713HIGH7.5A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle exce...
CVE-2024-10707MEDIUM6.5gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the...
CVE-2024-10650HIGH7.5An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could ...
CVE-2024-10648HIGH8.2A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi...
CVE-2024-10624HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the g...
CVE-2024-10572HIGH7.5In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` p...
CVE-2024-10569HIGH7.5A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The ...
CVE-2024-10553CRITICAL9.8A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitra...
CVE-2024-10550HIGH7.5A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) att...
CVE-2024-10549HIGH7.5A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. ...
CVE-2024-10513HIGH7.2A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting...
CVE-2024-10481MEDIUM6.5A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host...
CVE-2024-10457MEDIUM6.5Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito...
CVE-2024-10366MEDIUM6.5An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ...
CVE-2024-10363MEDIUM5.4In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ...
CVE-2024-10361CRITICAL9.1An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /ap...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now