3.5

CVSS3.0

CVE-2024-10724 - Stored XSS in IPV6 Section in phpipam/phpipam

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

7.1

CVSS3.0

CVE-2024-12216 - Arbitrary File Write via TarSlip in dmlc/gluon-cv

A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from URLs without proper sanitization, making it susceptible to a TarSlip vulnerability. Attacker…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

7.5

CVSS3.0

CVE-2024-7999 - Denial of Service in open-webui/open-webui

A vulnerability in open-webui/open-webui version 79778fa allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, r…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

7.5

CVSS3.0

CVE-2024-10572 - Denial of Service and Arbitrary File Write in h2oai/h2o-3

In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to arbitrary directories, leading to a denial of servi…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

6.8

CVSS3.0

CVE-2024-8955 - SSRF in composiohq/composio

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the system by exploiting the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

8.3

CVSS3.0

CVE-2024-10109 - Incorrect Authorization in mintplex-labs/anything-llm

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of s…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

8.8

CVSS3.0

CVE-2024-8489 - CSRF due to overly permissive CORS headers in modelscope/agentscope

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all …

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:54 p.m.

7.5

CVSS3.0

CVE-2024-8020 - Denial of Service in lightning-ai/pytorch-lightning

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:38 p.m.

7.1

CVSS3.0

CVE-2024-9000 - Improper Authorization and Duplicate Slug Vulnerability in lunary-ai/lunary

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing access control permits unauthorized users to create checklists, bypassing intended permission checks. Additi…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.

9.1

CVSS3.0

CVE-2024-8581 - Path Traversal in parisneo/lollms-webui

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:55 p.m.
Total resulsts: 286239
Page 39 of 28,624
Β« previous page Β» next page
Filters