7.5

CVSS3.0

CVE-2024-10267 - Information Disclosure in transformeroptimus/superagi

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server returns all informatโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:35 p.m.

9.3

CVSS3.0

CVE-2024-9309 - SSRF in POST /worker_generate_stream API endpoint in haotian-liu/llava

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthoriโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:35 p.m.

4.3

CVSS3.0

CVE-2024-6839 - Improper Regex Path Matching in corydolphin/flask-cors

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This mismatch in regex patterโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:35 p.m.

7.6

CVSS3.0

CVE-2024-9096 - Improper Authorization in lunary-ai/lunary

In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route lacks proper access control, such as middleware to ensure that only authorized users (e.g., project owners or admins) can modify checklist data. This vโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:35 p.m.

7.5

CVSS3.0

CVE-2024-8249 - Unauthenticated Denial of Service (DoS) in mintplex-labs/anything-llm

mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the API endpoint, causing a server crash due to an uncโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:36 p.m.

9.1

CVSS3.0

CVE-2024-10901 - Arbitrary File Write via DuckDB SQL Injection in eosphoros-ai/db-gpt

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enabling them to write arbitrary files to the victim's file systโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:36 p.m.

7.3

CVSS3.0

CVE-2024-9098 - Privilege Escalation in lunary-ai/lunary

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict admins from inviting โ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:36 p.m.

9.8

CVSS3.0

CVE-2024-8502 - Remote Code Execution via Deserialization in modelscope/agentscope

A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, where serialized input is deserialized using diโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:36 p.m.

4.3

CVSS3.0

CVE-2024-7046 - Improper Access Control in open-webui/open-webui

An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/auths/admin/details interface to retrieve the first admin (โ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:36 p.m.

8.1

CVSS3.0

CVE-2024-12880 - Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow

A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access to multiple tenants, they can manipulate their tenant access to query and accessโ€ฆ

๐Ÿ“… Published: March 20, 2025, 10:09 a.m. ๐Ÿ”„ Last Modified: March 20, 2025, 6:36 p.m.
Total resulsts: 286272
Page 40 of 28,628
ยซ previous page ยป next page
Filters