2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10359MEDIUM4.6In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca...
CVE-2024-10330MEDIUM6.5In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associa...
CVE-2024-10275HIGH7.3In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access ...
CVE-2024-10274MEDIUM6.5An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequ...
CVE-2024-10273MEDIUM6.5In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify...
CVE-2024-10272HIGH7.5lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any d...
CVE-2024-10267HIGH7.5An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can lea...
CVE-2024-10264CRITICAL9.8HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistenci...
CVE-2024-10252HIGH7.2A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa...
CVE-2024-10225HIGH7.5A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large n...
CVE-2024-10190CRITICAL9.8Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability ...
CVE-2024-10188HIGH7.5A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS...
CVE-2024-10110HIGH7.5In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of t...
CVE-2024-10109HIGH8.3A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access...
CVE-2024-10096——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-10051HIGH7.5Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in ...
CVE-2024-10047MEDIUM5.3parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can l...
CVE-2024-10019MEDIUM6.7A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a...
CVE-2024-0640MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerabilit...
CVE-2024-0245MEDIUM5.5A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln...
CVE-2024-54016MEDIUM4.3Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue...
CVE-2024-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incu...
CVE-2024-12016CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM ...
CVE-2024-13881HIGH7.1The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13880HIGH7.1The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the pa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now