4.7

CVSS3.0

CVE-2024-8029 - Stored XSS in imartinez/privategpt

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:55 p.m.

6.5

CVSS3.0

CVE-2024-9418 - Insufficiently Protected Credentials in transformeroptimus/superagi

In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

10

CVSS3.0

CVE-2024-12909 - SQL Injection to RCE in run-llama/llama_index

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code e…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

7.5

CVSS3.0

CVE-2024-9363 - Unauthorized File Deletion in polyaxon/polyaxon

An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpec…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

8

CVSS3.0

CVE-2024-9847 - Cross-Site Request Forgery (CSRF) in flatpressblog/flatpress

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a request to the FlatPress…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

7.5

CVSS3.0

CVE-2024-8984 - Denial of Service (DoS) in berriai/litellm

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource …

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

9.1

CVSS3.0

CVE-2024-10902 - Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability in…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

7.5

CVSS3.0

CVE-2024-10821 - Denial of Service (DoS) in invoke-ai/invokeai

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundari…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

4.3

CVSS3.0

CVE-2024-12580 - Logs Debug Injection in danny-avila/librechat

A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential log injection attac…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:56 p.m.

7.7

CVSS3.0

CVE-2024-11031 - SSRF in binary-husky/gpt_academic

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: March 20, 2025, 6:57 p.m.
Total resulsts: 286194
Page 36 of 28,620
« previous page » next page
Filters