6.3

CVSS3.0

CVE-2024-10019 - Path Traversal and OS Command Injection in parisneo/lollms-webui

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the `app_name` parameter, enabling an attacker to upload a malicious `server.py` file and execute arbitrary code b…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

9.8

CVSS3.0

CVE-2024-9070 - Deserialization Vulnerability in BentoML's Runner Server in bentoml/bentoml

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the server, causing severe harm. The vulnerability is triggered when the args-number parameter is great…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

6.5

CVSS3.0

CVE-2024-6841 - CSRF in vanna-ai/vanna

A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app that provide SQL functionality are implemented as simple GET requests, making them susceptible to CSRF att…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

7.5

CVSS3.0

CVE-2024-10907 - Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat

In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

6.5

CVSS3.0

CVE-2024-9159 - Incorrect Authorization in gaizhenbiao/chuanhuchatgpt

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

6.8

CVSS3.0

CVE-2024-9107 - Stored XSS in gaizhenbiao/chuanhuchatgpt

A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in chat history uploads. Specifically, the sanitization logic fails to handle HTML tags within code …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

9.6

CVSS3.0

CVE-2024-11045 - Cross-Site WebSocket Hijacking (CSWSH) in automatic1111/stable-diffusion-webui

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:786…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

7.5

CVSS3.0

CVE-2024-9056 - Denial of Service in bentoml/bentoml

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive r…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

7.5

CVSS3.0

CVE-2024-10550 - Denial of Service by ReDOS in h2oai/h2o-3

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexit…

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.

6.5

CVSS3.0

CVE-2024-9447 - Exposure of Sensitive Information in transformeroptimus/superagi

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This …

πŸ“… Published: March 20, 2025, 10:10 a.m. πŸ”„ Last Modified: March 20, 2025, 10:15 a.m.
Total resulsts: 286100
Page 18 of 28,610
Β« previous page Β» next page
Filters