2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10725 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an ... |
| CVE-2024-10724 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NA... |
| CVE-2024-10723 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al... |
| CVE-2024-10722 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows atta... |
| CVE-2024-10721 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability al... |
| CVE-2024-10720 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in t... |
| CVE-2024-10719 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options ... |
| CVE-2024-10718 | HIGH | 7.5 | 0.3% | Mar 20, 2025 | In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca... |
| CVE-2024-10714 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by addin... |
| CVE-2024-10713 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle exce... |
| CVE-2024-10707 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the... |
| CVE-2024-10650 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could ... |
| CVE-2024-10648 | HIGH | 8.2 | 0.7% | Mar 20, 2025 | A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. Thi... |
| CVE-2024-10624 | HIGH | 7.5 | 1.0% | Mar 20, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the g... |
| CVE-2024-10572 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` p... |
| CVE-2024-10569 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The ... |
| CVE-2024-10553 | CRITICAL | 9.8 | 1.4% | Mar 20, 2025 | A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitra... |
| CVE-2024-10550 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) att... |
| CVE-2024-10549 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. ... |
| CVE-2024-10513 | HIGH | 7.2 | 0.8% | Mar 20, 2025 | A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting... |
| CVE-2024-10481 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host... |
| CVE-2024-10457 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt reposito... |
| CVE-2024-10366 | MEDIUM | 6.5 | 0.3% | Mar 20, 2025 | An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat ... |
| CVE-2024-10363 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and ... |
| CVE-2024-10361 | CRITICAL | 9.1 | 0.9% | Mar 20, 2025 | An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /ap... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now