7.5

CVSS3.0

CVE-2024-8028 - Denial of Service in danswer-ai/danswer

A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering th…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-10935 - Unauthenticated DoS via Multipart Boundary in automatic1111/stable-diffusion-webui

automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, le…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.2

CVSS3.0

CVE-2024-10513 - Path Traversal in mintplex-labs/anything-llm

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anythingllm.db' database file. By exploiting the vulnerab…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 14, 2025, 2:01 p.m.

7.5

CVSS3.0

CVE-2024-10829 - Denial of Service (DoS) via Multipart Boundary in eosphoros-ai/db-gpt

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-8438 - Path Traversal in modelscope/agentscope

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:49 a.m.

7.5

CVSS3.0

CVE-2024-12065 - Local File Inclusion in haotian-liu/llava

A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:47 p.m.

5.3

CVSS3.1

CVE-2024-11167 - Improper Access Control in danny-avila/librechat

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 15, 2025, 11:15 a.m.

8.1

CVSS3.0

CVE-2024-8060 - Remote Code Execution in OpenWebUI via Arbitrary File Upload

OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The application performs insufficient validation on the `file.content_type` and allows user-controlled filenames, leading to a path traversal vulnerabilit…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.5

CVSS3.0

CVE-2024-9362 - Directory Traversal in polyaxon/polyaxon

An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization, leading to sensitive information disclosure. The issue enabl…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 20, 2025, 6:34 p.m.

7.5

CVSS3.1

CVE-2025-0315 - Allocation of Resources Without Limits or Throttling in ollama/ollama

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 2, 2025, 4:02 p.m.
Total resulsts: 343048
Page 5672 of 34,305
Β« previous page Β» next page
Filters