2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31802MEDIUM6.3DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.
CVE-2024-6250HIGH7.5An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint ...
CVE-2024-6139HIGH7.3A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability...
CVE-2024-6090HIGH7.5A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other ...
CVE-2024-6086MEDIUM4.3In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organi...
CVE-2024-6085HIGH8.6A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerabilit...
CVE-2024-6038HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt....
CVE-2024-5980CRITICAL9.8A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path t...
CVE-2024-5979HIGH7.5In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class ...
CVE-2024-5936MEDIUM6.1An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' param...
CVE-2024-5935MEDIUM5.4A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete ...
CVE-2024-5933MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest versi...
CVE-2024-5885HIGH8.6stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not p...
CVE-2024-5826CRITICAL9.8In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt i...
CVE-2024-5824HIGH7.4A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an atta...
CVE-2024-5822CRITICAL9.8A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatG...
CVE-2024-5820HIGH8.8An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious websit...
CVE-2024-5755MEDIUM5.3In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the em...
CVE-2024-5751CRITICAL9.8BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulner...
CVE-2024-5714MEDIUM6.8In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissi...
CVE-2024-5710MEDIUM6.5berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vuln...
CVE-2024-4578HIGH8.4This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate...
CVE-2024-3331MEDIUM6.8Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spo...
CVE-2024-3330CRITICAL9.9Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In th...
CVE-2024-3043HIGH7.5An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their net...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now