8.8

CVSS3.0

CVE-2024-11170 - Path Traversal in danny-avila/librechat

A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:59 p.m.

4.3

CVSS3.0

CVE-2024-11821 - Privilege Escalation in langgenius/dify

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /consolโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:59 p.m.

7.5

CVSS3.0

CVE-2024-12068 - Server-Side Request Forgery in haotian-liu/llava

A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, suchโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7 p.m.

6.5

CVSS3.0

CVE-2024-11037 - Path Traversal in binary-husky/gpt_academic

A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as the OpenAI API key. This vulnerability is exploitable on Windows operating systeโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7 p.m.

7.5

CVSS3.0

CVE-2024-8763 - Regular Expression Denial of Service (ReDoS) in lunary-ai/lunary

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in the compileTextTemplate function. The affected version is git be54057. An attacker can exploit this vulnerability by manipulating the regular expression /{{(.*?)}}/g, causing the โ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7 p.m.

8.4

CVSS3.0

CVE-2024-7990 - Stored Cross-Site Scripting in open-webui/open-webui

A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7 p.m.

7.5

CVSS3.0

CVE-2024-12761 - Denial of Service in brycedrennan/imaginairy

A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerability is present in the `/api/stablestudio/generate` endpoint, which can be exploited by sending an invalid request. This causes the server process to terminate abruptly, outputtingโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7 p.m.

7.5

CVSS3.0

CVE-2024-10225 - Denial of Service in haotian-liu/llava

A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessiโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7 p.m.

7.5

CVSS3.0

CVE-2024-11449 - Server-Side Request Forgery in haotian-liu/llava

A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validationโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7:01 p.m.

7.5

CVSS3.0

CVE-2024-7779 - ReDoS (Regular Expression Denial of Service) in danswer-ai/danswer

A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.

๐Ÿ“… Published: March 20, 2025, 10:08 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7:01 p.m.
Total resulsts: 286136
Page 34 of 28,614
ยซ previous page ยป next page
Filters