2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10359 | MEDIUM | 4.6 | 0.3% | Mar 20, 2025 | In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user ca... |
| CVE-2024-10330 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associa... |
| CVE-2024-10275 | HIGH | 7.3 | 0.5% | Mar 20, 2025 | In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access ... |
| CVE-2024-10274 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequ... |
| CVE-2024-10273 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify... |
| CVE-2024-10272 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any d... |
| CVE-2024-10267 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can lea... |
| CVE-2024-10264 | CRITICAL | 9.8 | 0.9% | Mar 20, 2025 | HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistenci... |
| CVE-2024-10252 | HIGH | 7.2 | 0.7% | Mar 20, 2025 | A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sa... |
| CVE-2024-10225 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large n... |
| CVE-2024-10190 | CRITICAL | 9.8 | 1.0% | Mar 20, 2025 | Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability ... |
| CVE-2024-10188 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS... |
| CVE-2024-10110 | HIGH | 7.5 | 0.6% | Mar 20, 2025 | In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of t... |
| CVE-2024-10109 | HIGH | 8.3 | 0.5% | Mar 20, 2025 | A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access... |
| CVE-2024-10096 | — | — | — | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-10051 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in ... |
| CVE-2024-10047 | MEDIUM | 5.3 | 1.0% | Mar 20, 2025 | parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can l... |
| CVE-2024-10019 | MEDIUM | 6.7 | 0.8% | Mar 20, 2025 | A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a... |
| CVE-2024-0640 | MEDIUM | 4.8 | 0.2% | Mar 20, 2025 | A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerabilit... |
| CVE-2024-0245 | MEDIUM | 5.5 | 0.2% | Mar 20, 2025 | A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln... |
| CVE-2024-54016 | MEDIUM | 4.3 | 0.6% | Mar 20, 2025 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue... |
| CVE-2024-47552 | CRITICAL | 9.8 | 1.1% | Mar 20, 2025 | Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incu... |
| CVE-2024-12016 | CRITICAL | 9.8 | 0.4% | Mar 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM ... |
| CVE-2024-13881 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13880 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the pa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now