7.5

CVSS3.0

CVE-2024-8859 - Path Traversal in mlflow/mlflow

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while part…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Aug. 5, 2025, 4:15 p.m.

9.8

CVSS3.0

CVE-2024-10190 - Unauthenticated Remote Code Execution in ElasticRendezvousHandler in horovod/horovod

Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. Specifically, the `_put_value` method in `ElasticRendezvousHa…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Dec. 11, 2025, 6:19 p.m.

7.5

CVSS3.0

CVE-2024-8028 - Denial of Service in danswer-ai/danswer

A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering th…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-10935 - Unauthenticated DoS via Multipart Boundary in automatic1111/stable-diffusion-webui

automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, le…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.2

CVSS3.0

CVE-2024-10513 - Path Traversal in mintplex-labs/anything-llm

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anythingllm.db' database file. By exploiting the vulnerab…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: July 14, 2025, 2:01 p.m.

7.5

CVSS3.0

CVE-2024-10829 - Denial of Service (DoS) via Multipart Boundary in eosphoros-ai/db-gpt

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-8438 - Path Traversal in modelscope/agentscope

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Aug. 1, 2025, 1:49 a.m.

7.5

CVSS3.0

CVE-2024-12065 - Local File Inclusion in haotian-liu/llava

A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component.

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 21, 2025, 2:47 p.m.

5.3

CVSS3.1

CVE-2024-11167 - Improper Access Control in danny-avila/librechat

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: July 15, 2025, 11:15 a.m.

8.1

CVSS3.0

CVE-2024-8060 - Remote Code Execution in OpenWebUI via Arbitrary File Upload

OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The application performs insufficient validation on the `file.content_type` and allows user-controlled filenames, leading to a path traversal vulnerabilit…

📅 Published: March 20, 2025, 10:09 a.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 343040
Page 5671 of 34,304
« previous page » next page
Filters