2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31802 | MEDIUM | 6.3 | 0.3% | Jun 27, 2024 | DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code. |
| CVE-2024-6250 | HIGH | 7.5 | 2.0% | Jun 27, 2024 | An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint ... |
| CVE-2024-6139 | HIGH | 7.3 | 0.5% | Jun 27, 2024 | A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability... |
| CVE-2024-6090 | HIGH | 7.5 | 0.9% | Jun 27, 2024 | A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other ... |
| CVE-2024-6086 | MEDIUM | 4.3 | 0.4% | Jun 27, 2024 | In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organi... |
| CVE-2024-6085 | HIGH | 8.6 | 0.6% | Jun 27, 2024 | A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerabilit... |
| CVE-2024-6038 | HIGH | 7.5 | 0.7% | Jun 27, 2024 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt.... |
| CVE-2024-5980 | CRITICAL | 9.8 | 1.3% | Jun 27, 2024 | A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path t... |
| CVE-2024-5979 | HIGH | 7.5 | 0.8% | Jun 27, 2024 | In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class ... |
| CVE-2024-5936 | MEDIUM | 6.1 | 28.9% | Jun 27, 2024 | An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' param... |
| CVE-2024-5935 | MEDIUM | 5.4 | 0.2% | Jun 27, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete ... |
| CVE-2024-5933 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest versi... |
| CVE-2024-5885 | HIGH | 8.6 | 0.6% | Jun 27, 2024 | stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not p... |
| CVE-2024-5826 | CRITICAL | 9.8 | 0.9% | Jun 27, 2024 | In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt i... |
| CVE-2024-5824 | HIGH | 7.4 | 0.4% | Jun 27, 2024 | A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an atta... |
| CVE-2024-5822 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatG... |
| CVE-2024-5820 | HIGH | 8.8 | 0.8% | Jun 27, 2024 | An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious websit... |
| CVE-2024-5755 | MEDIUM | 5.3 | 0.3% | Jun 27, 2024 | In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the em... |
| CVE-2024-5751 | CRITICAL | 9.8 | 0.9% | Jun 27, 2024 | BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulner... |
| CVE-2024-5714 | MEDIUM | 6.8 | 0.5% | Jun 27, 2024 | In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissi... |
| CVE-2024-5710 | MEDIUM | 6.5 | 0.4% | Jun 27, 2024 | berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vuln... |
| CVE-2024-4578 | HIGH | 8.4 | 0.5% | Jun 27, 2024 | This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate... |
| CVE-2024-3331 | MEDIUM | 6.8 | 0.4% | Jun 27, 2024 | Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spo... |
| CVE-2024-3330 | CRITICAL | 9.9 | 0.6% | Jun 27, 2024 | Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In th... |
| CVE-2024-3043 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their net... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now