7.5

CVSS3.0

CVE-2024-9606 - Improper Output Neutralization for Logs in berriai/litellm

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amou…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

3.5

CVSS3.0

CVE-2024-10723 - Stored XSS in phpipam/phpipam

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact of this vul…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

6.5

CVSS3.0

CVE-2024-12775 - SSRF in langgenius/dify

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenA…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

7.5

CVSS3.0

CVE-2024-10110 - Denial of Service in aimhubio/aim

In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server becomes unable to respond to other requests.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

4.7

CVSS3.0

CVE-2024-8029 - Stored XSS in imartinez/privategpt

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

6.5

CVSS3.0

CVE-2024-9418 - Insufficiently Protected Credentials in transformeroptimus/superagi

In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:56 p.m.

10

CVSS3.0

CVE-2024-12909 - SQL Injection to RCE in run-llama/llama_index

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code e…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:56 p.m.

7.5

CVSS3.0

CVE-2024-9363 - Unauthorized File Deletion in polyaxon/polyaxon

An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpec…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:56 p.m.

8

CVSS3.0

CVE-2024-9847 - Cross-Site Request Forgery (CSRF) in flatpressblog/flatpress

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a request to the FlatPress…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:56 p.m.

7.5

CVSS3.0

CVE-2024-8984 - Denial of Service (DoS) in berriai/litellm

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource …

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:56 p.m.
Total resulsts: 286208
Page 37 of 28,621
Β« previous page Β» next page
Filters