7.5

CVSS3.0

CVE-2024-8020 - Denial of Service in lightning-ai/pytorch-lightning

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

7.1

CVSS3.0

CVE-2024-9000 - Improper Authorization and Duplicate Slug Vulnerability in lunary-ai/lunary

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing access control permits unauthorized users to create checklists, bypassing intended permission checks. Additi…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

9.1

CVSS3.0

CVE-2024-8581 - Path Traversal in parisneo/lollms-webui

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

6.1

CVSS3.0

CVE-2024-10812 - Open Redirect in binary-husky/gpt_academic

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers to conduct phishing a…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

7.5

CVSS3.0

CVE-2024-9606 - Improper Output Neutralization for Logs in berriai/litellm

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amou…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

3.5

CVSS3.0

CVE-2024-10723 - Stored XSS in phpipam/phpipam

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact of this vul…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

6.5

CVSS3.0

CVE-2024-12775 - SSRF in langgenius/dify

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenA…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

7.5

CVSS3.0

CVE-2024-10110 - Denial of Service in aimhubio/aim

In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server becomes unable to respond to other requests.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

4.7

CVSS3.0

CVE-2024-8029 - Stored XSS in imartinez/privategpt

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

6.5

CVSS3.0

CVE-2024-9418 - Insufficiently Protected Credentials in transformeroptimus/superagi

In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:56 p.m.
Total resulsts: 286222
Page 38 of 28,623
Β« previous page Β» next page
Filters